Логотип exploitDog
bind:CVE-2023-20059
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-20059

Количество 3

Количество 3

nvd логотип

CVE-2023-20059

почти 3 года назад

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-723j-vwr2-6865

почти 3 года назад

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2023-02299

почти 3 года назад

Уязвимость реализации технологии для быстрого определения и конфигурирования устройств Cisco Network Plug-and-Play (PnP) центра управления сетью Cisco DNA Center, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-20059

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-723j-vwr2-6865

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-02299

Уязвимость реализации технологии для быстрого определения и конфигурирования устройств Cisco Network Plug-and-Play (PnP) центра управления сетью Cisco DNA Center, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу