CVE-2023-20055
published 2023-03-23CVE-2023-20055: A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.74%
50.6th percentile
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | < 2.3.3.6 | 2.3.3.6 |
| cisco | catalyst_center | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3ff8-m2gm-qf6j: A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the we
ghsa_unreviewed·2023-03-23
CVE-2023-20055 [HIGH] CWE-200 GHSA-3ff8-m2gm-qf6j: A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the we
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials.
Cisco
Cisco DNA Center Privilege Escalation Vulnerability
vendor_cisco·2023-03-22·CVSS 8.0
CVE-2023-20055 [HIGH] CWE-200 Cisco DNA Center Privilege Escalation Vulnerability
Cisco DNA Center Privilege Escalation Vulnerability
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device.
This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
T
Cisco
Cisco DNA Center Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20055 Cisco DNA Center Privilege Escalation Vulnerability
CVE-2023-20055: Cisco DNA Center Privilege Escalation Vulnerability
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-200, CWE-200
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published