Логотип exploitDog
bind:CVE-2023-20034
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-20034

Количество 4

Количество 4

nvd логотип

CVE-2023-20034

больше 2 лет назад

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-20034

больше 2 лет назад

Vulnerability in the Elasticsearch database used in the of Cisco SD-WA ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vph8-3839-qfq3

больше 2 лет назад

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-06359

больше 2 лет назад

Уязвимость поисковой системы Elasticsearch централизованной системы управления сетью Cisco Catalyst SD-WAN Manager (ранее Cisco SD-WAN vManage), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WA ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vph8-3839-qfq3

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-06359

Уязвимость поисковой системы Elasticsearch централизованной системы управления сетью Cisco Catalyst SD-WAN Manager (ранее Cisco SD-WAN vManage), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу