Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20254

Опубликовано: 27 сент. 2023
Источник: nvd
CVSS3: 7.2
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.

This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:sd-wan_manager:*:*:*:*:*:*:*:*
Версия до 20.6.3.4 (исключая)
cpe:2.3:a:cisco:sd-wan_manager:*:*:*:*:*:*:*:*
Версия от 20.7 (включая) до 20.9.3.2 (исключая)
cpe:2.3:a:cisco:sd-wan_manager:*:*:*:*:*:*:*:*
Версия от 20.10 (включая) до 20.10.1.2 (исключая)
cpe:2.3:a:cisco:sd-wan_manager:*:*:*:*:*:*:*:*
Версия от 20.11 (включая) до 20.11.1.2 (исключая)

EPSS

Процентиль: 55%
0.00322
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.2
github
больше 2 лет назад

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled. This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.

CVSS3: 7.2
fstec
больше 2 лет назад

Уязвимость централизованной системы управления сетью Cisco Catalyst SD-WAN Manager, связанная с недостатками процедуры авторизации, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 55%
0.00322
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-732