CVE-2022-20630
published 2022-02-10CVE-2022-20630: A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This…
PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.23%
13.3th percentile
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | >= 2.1.2.0 < 2.2.2.8 | 2.2.2.8 |
| cisco | catalyst_center | >= 2.2.3.0 < 2.2.3.4 | 2.2.3.4 |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·2022-02-02·CVSS 4.4
CVE-2022-20630 [MEDIUM] CWE-200 Cisco DNA Center Information Disclosure Vulnerability
Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text.
This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-i
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20630 Cisco DNA Center Information Disclosure Vulnerability
CVE-2022-20630: Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-200, CWE-200
Bug IDs: CSCvz64017
GHSA
GHSA-86m6-8m8r-f858: A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text
ghsa_unreviewed·2022-02-11
CVE-2022-20630 [MEDIUM] CWE-200 GHSA-86m6-8m8r-f858: A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-10
Published