CVE-2022-20830

Severity
5.3MEDIUM
EPSS
0.3%
top 49.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateOct 11

Description

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDcisco/sd-wan_vmanage18.420.3.4.1
NVDcisco/catalyst_sd-wan_manager20.420.6.1+1

🔴Vulnerability Details

2
GHSA
GHSA-8c9g-fr4h-6x8r: A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unau2022-10-11
CVEList
Cisco Software-Defined Application Visibility and Control on Cisco vManage Authentication Bypass Vulnerability2022-10-10

📋Vendor Advisories

1
Cisco
Cisco Software-Defined Application Visibility and Control on Cisco vManage Authentication Bypass Vulnerability2022-09-28
CVE-2022-20830 (MEDIUM CVSS 5.3) | A vulnerability in authentication m | cvebase.io