← Back

CVE-2022-20680

nvd nist
Published: Feb 10, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper enforcement of Administrator privilege levels for low-value sensitive data. An attacker with read-only Administrator access to the web-based management interface could exploit this vulnerability by sending a malicious HTTP request to the page that contains the sensitive data. A successful exploit could allow the attacker to collect sensitive information about users of the system and orders that have been placed using the application.

Affected (17)

1 product
Prime Service Catalog
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 12.0
Version 12.1
Version 12.1 patch10
Version 12.1 patch11
Version 12.1 patch12
Version 12.1 patch13
Version 12.1 patch14
Version 12.1 patch15
Version 12.1 patch16
Version 12.1 patch17
Version 12.1 patch2
Version 12.1 patch3
Version 12.1 patch4
Version 12.1 patch6
Version 12.1 patch7
Version 12.1 patch8
Version 12.1 patch9

Timeline

No history available yet.