CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-20214

CVSS 9.1v3.1pub. 2023-08-03upd. 2024-11-21

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Cisco Catalyst Sd Wan Manager

    APP
    Cisco
    20.6.3.320.6.4 – 20.6.4.2 (excl.)20.6.5 – 20.6.5.5 (excl.)20.7 – 20.9.3.2 (excl.)20.11 – 20.11.1.2 (excl.)
  • Cisco Sd Wan Vmanage

    APP
    Cisco
    20.10 – 20.10.1.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-20182CRITICAL10.0⚠ KEVPL ✓same product

Cisco Catalyst SD-WAN — pominięcie uwierzytelnienia z dostępem administracyjnym

CVE-2026-20127CRITICAL10.0⚠ KEVPL ✓same product

Cisco Catalyst SD-WAN — ominięcie uwierzytelnienia peering i przejęcie uprawnień

CVE-2026-20129CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w API Cisco Catalyst SD-WAN Manager

CVE-2023-20252CRITICAL9.8PL ✓same product

Cisco Catalyst SD-WAN Manager — Auth Bypass przez SAML API

CVE-2021-1506CRITICAL9.8PL ✓same product

Krytyczne podatności w Cisco SD-WAN vManage — RCE i eskalacja uprawnień