Lucene search

K
nvd[email protected]NVD:CVE-2023-20254
HistorySep 27, 2023 - 6:15 p.m.

CVE-2023-20254

2023-09-2718:15:11
CWE-732
web.nvd.nist.gov
vulnerability
session management
cisco catalyst sd-wan manager
multi-tenant
exploit
unauthorized access
configuration changes
denial of service

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.

This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.

Affected configurations

NVD
Node
ciscosd-wan_managerRange<20.6.3.4
OR
ciscosd-wan_managerRange20.720.9.3.2
OR
ciscosd-wan_managerRange20.1020.10.1.2
OR
ciscosd-wan_managerRange20.1120.11.1.2

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

Related for NVD:CVE-2023-20254