CVE-2023-20223Improper Access Control in Cisco DNA Center

Severity
8.2HIGHNVD
CNA8.6
EPSS
0.2%
top 61.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27

Description

A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read and modify data that is handled by an internal service on the affected devic

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 3.9 | Impact: 4.2

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2023-20223: A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an interna2023-09-27
GHSA
GHSA-g63p-vxrj-44x5: A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an interna2023-09-27

📋Vendor Advisories

1
Cisco
Cisco DNA Center API Insufficient Access Control Vulnerability2023-09-27
CVE-2023-20223 — Improper Access Control in Cisco | cvebase