CVE-2022-20830
published 2022-10-10CVE-2022-20830: A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an…
medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow the attacker to view managed device names, SD-AVC logs, and SD-AVC DNS server IP addresses.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.4 < 20.6.1 | 20.6.1 |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | sd-wan_vmanage | >= 18.4 < 20.3.4.1 | 20.3.4.1 |
| cisco | software-defined_application_visibility_and_control_on_cisco_vmanage | — | — |