cbcvebase.
CVE-2022-20844
published 2022-09-30

CVE-2022-20844: A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password combination. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow the attacker to view managed device names, SD-AVC logs, and SD-AVC DNS server IP addresses.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscocisco_sd-wan_vmanage
ciscosd-wan
ciscosd-wan
ciscosd-wan
ciscosd-wan
ciscosd-wan>= 20.4.1 < 20.6.320.6.3
ciscosoftware-defined_application_visibility_and_control_on_cisco_vmanage_static_user