CVE-2023-20214
published 2023-08-03CVE-2023-20214: A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to…
PriorityP265critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.92%
56.2th percentile
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.11 < 20.11.1.2 | 20.11.1.2 |
| cisco | catalyst_sd-wan_manager | >= 20.6.4 < 20.6.4.2 | 20.6.4.2 |
| cisco | catalyst_sd-wan_manager | >= 20.6.5 < 20.6.5.5 | 20.6.5.5 |
| cisco | catalyst_sd-wan_manager | >= 20.7 < 20.9.3.2 | 20.9.3.2 |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | cisco_sd-wan_vmanage | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability only affects the REST API endpoint of Cisco SD-WAN vManage; detections should focus on unauthenticated or anomalous REST API requests to the vManage instance, not the web-based management interface or CLI. ↗
- →Look for crafted/malformed API requests to the vManage REST API from unauthenticated sources, particularly those that succeed in retrieving or modifying configuration data without valid credentials. ↗
- →Monitor for unauthenticated REST API access resulting in configuration reads or limited writes on Cisco SD-WAN vManage; successful exploitation allows both information retrieval and configuration modification. ↗
- ·No workarounds are available for this vulnerability; the only remediation is applying Cisco's software updates. ↗
- ·The vulnerability is tracked under two Cisco bug IDs (CSCwf76218 and CSCwf82344), which may correspond to different affected software trains or configurations. ↗
- ·The root cause is insufficient request validation in the REST API authentication flow (CWE-287: Improper Authentication), meaning authentication checks can be bypassed entirely by a remote, unauthenticated attacker. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_cisco9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
vendor_cisco·2023-07-12·CVSS 9.1
CVE-2023-20214 [CRITICAL] CWE-287 Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management int
Cisco
Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20214 Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
CVE-2023-20214: Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based
GHSA
GHSA-m62w-7qr8-gjmc: A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote atta
ghsa_unreviewed·2023-08-04
CVE-2023-20214 [CRITICAL] CWE-287 GHSA-m62w-7qr8-gjmc: A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote atta
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-03
Published