Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20059

Опубликовано: 23 мар. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия до 2.3.3.7 (исключая)
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия от 2.3.4.0 (включая) до 2.3.5.0 (исключая)

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-555
CWE-312

Связанные уязвимости

CVSS3: 6.5
github
почти 3 года назад

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 4.3
fstec
почти 3 года назад

Уязвимость реализации технологии для быстрого определения и конфигурирования устройств Cisco Network Plug-and-Play (PnP) центра управления сетью Cisco DNA Center, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-555
CWE-312