CVE-2023-20059
published 2023-03-23CVE-2023-20059: A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.41%
33.0th percentile
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center | < 2.3.3.7 | 2.3.3.7 |
| cisco | catalyst_center | >= 2.3.4.0 < 2.3.5.0 | 2.3.5.0 |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·2023-03-22·CVSS 4.3
CVE-2023-20059 [MEDIUM] CWE-555 Cisco DNA Center Information Disclosure Vulnerability
Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials.
This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advis
Cisco
Cisco DNA Center Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20059 Cisco DNA Center Information Disclosure Vulnerability
CVE-2023-20059: Cisco DNA Center Information Disclosure Vulnerability
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-555, CWE-555
Bug IDs:
GHSA
GHSA-723j-vwr2-6865: A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker
ghsa_unreviewed·2023-03-23
CVE-2023-20059 [MEDIUM] CWE-312 GHSA-723j-vwr2-6865: A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published