← Back

CVE-2023-20261

nvd nist
Published: Oct 18, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.

Affected (99)

1 product
Catalyst Sd Wan Manager
Configuration A
99 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 17.2.10
Version 17.2.4
Version 17.2.5
Version 17.2.6
Version 17.2.7
Version 17.2.8
Version 17.2.9
Version 18.2.0
Version 18.3.0
Version 18.3.1.1
Version 18.3.1
Version 18.3.3.1
Version 18.3.3
Version 18.3.4
Version 18.3.5
Version 18.3.6.1
Version 18.3.7
Version 18.3.8
Version 18.4.0.1
Version 18.4.0
Version 18.4.1
Version 18.4.302
Version 18.4.303
Version 18.4.3
Version 18.4.4
Version 18.4.5
Version 18.4.6
Version 19.1.0
Version 19.2.097
Version 19.2.099
Version 19.2.0
Version 19.2.1
Version 19.2.2
Version 19.2.31
Version 19.2.3
Version 19.2.4
Version 19.2.929
Version 19.3.0
Version 20.1.1.1
Version 20.1.12
Version 20.1.1
Version 20.1.2
Version 20.1.3
Version 20.3.1
Version 20.3.2.1
Version 20.3.2
Version 20.3.3.1
Version 20.3.3
Version 20.3.4.1
Version 20.3.4.2
Version 20.3.4.3
Version 20.3.4
Version 20.3.5.1
Version 20.3.5
Version 20.3.6
Version 20.3.7.1
Version 20.3.7.2
Version 20.3.7
Version 20.3.8
Version 20.4.1.1
Version 20.4.1.2
Version 20.4.1
Version 20.4.2.1
Version 20.4.2.2
Version 20.4.2.3
Version 20.4.2
Version 20.5.1.1
Version 20.5.1.2
Version 20.5.1
Version 20.6.1.1
Version 20.6.1.2
Version 20.6.1
Version 20.6.2.1
Version 20.6.2.2
Version 20.6.2
Version 20.6.3.0.45
Version 20.6.3.0.46
Version 20.6.3.0.47
Version 20.6.3.1
Version 20.6.3.2
Version 20.6.3.3
Version 20.6.3.4
Version 20.6.3
Version 20.6.4.0.21
Version 20.6.4.1
Version 20.6.4.2
Version 20.6.4
Version 20.6.5.1.10
Version 20.6.5.1.11
Version 20.6.5.1.13
Version 20.6.5.1.7
Version 20.6.5.1.9
Version 20.6.5.1
Version 20.6.5.2.4
Version 20.6.5.2.8
Version 20.6.5.2
Version 20.6.5.4
Version 20.6.5.5
Version 20.6.5

Timeline

No history available yet.