cbcvebase.
CVE-2023-20059
published 2023-03-23

CVE-2023-20059: A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocatalyst_center< 2.3.3.72.3.3.7
ciscocatalyst_center>= 2.3.4.0 < 2.3.5.02.3.5.0
ciscocisco_digital_network_architecture_center
ciscodna_center