Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20136

Опубликовано: 28 июн. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials.

This vulnerability is due to improper role-based access control (RBAC) of certain OpenAPI operations. An attacker could exploit this vulnerability by issuing a crafted OpenAPI function call with valid credentials. A successful exploit could allow the attacker to execute OpenAPI operations that are reserved for the Administrator user, including the creation and deletion of user labels.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*
Версия до 3.7.1.40 (исключая)

EPSS

Процентиль: 28%
0.001
Низкий

4.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-648
CWE-269

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access control (RBAC) of certain OpenAPI operations. An attacker could exploit this vulnerability by issuing a crafted OpenAPI function call with valid credentials. A successful exploit could allow the attacker to execute OpenAPI operations that are reserved for the Administrator user, including the creation and deletion of user labels.

CVSS3: 4.3
fstec
больше 3 лет назад

Уязвимость интерфейса OpenAPI средства защиты рабочих нагрузок мультиоблачных центров обработки данных Cisco Secure Workload (ранее Tetration), позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 28%
0.001
Низкий

4.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-648
CWE-269