Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20261


A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.


Published

2023-10-18T17:15:08.467

Last Modified

2024-11-21T07:41:01.273

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco catalyst_sd-wan_manager 17.2.4 Yes
Application cisco catalyst_sd-wan_manager 17.2.5 Yes
Application cisco catalyst_sd-wan_manager 17.2.6 Yes
Application cisco catalyst_sd-wan_manager 17.2.7 Yes
Application cisco catalyst_sd-wan_manager 17.2.8 Yes
Application cisco catalyst_sd-wan_manager 17.2.9 Yes
Application cisco catalyst_sd-wan_manager 17.2.10 Yes
Application cisco catalyst_sd-wan_manager 18.2.0 Yes
Application cisco catalyst_sd-wan_manager 18.3.0 Yes
Application cisco catalyst_sd-wan_manager 18.3.1 Yes
Application cisco catalyst_sd-wan_manager 18.3.1.1 Yes
Application cisco catalyst_sd-wan_manager 18.3.3 Yes
Application cisco catalyst_sd-wan_manager 18.3.3.1 Yes
Application cisco catalyst_sd-wan_manager 18.3.4 Yes
Application cisco catalyst_sd-wan_manager 18.3.5 Yes
Application cisco catalyst_sd-wan_manager 18.3.6.1 Yes
Application cisco catalyst_sd-wan_manager 18.3.7 Yes
Application cisco catalyst_sd-wan_manager 18.3.8 Yes
Application cisco catalyst_sd-wan_manager 18.4.0 Yes
Application cisco catalyst_sd-wan_manager 18.4.0.1 Yes
Application cisco catalyst_sd-wan_manager 18.4.1 Yes
Application cisco catalyst_sd-wan_manager 18.4.3 Yes
Application cisco catalyst_sd-wan_manager 18.4.4 Yes
Application cisco catalyst_sd-wan_manager 18.4.5 Yes
Application cisco catalyst_sd-wan_manager 18.4.6 Yes
Application cisco catalyst_sd-wan_manager 18.4.302 Yes
Application cisco catalyst_sd-wan_manager 18.4.303 Yes
Application cisco catalyst_sd-wan_manager 19.1.0 Yes
Application cisco catalyst_sd-wan_manager 19.2.0 Yes
Application cisco catalyst_sd-wan_manager 19.2.1 Yes
Application cisco catalyst_sd-wan_manager 19.2.2 Yes
Application cisco catalyst_sd-wan_manager 19.2.3 Yes
Application cisco catalyst_sd-wan_manager 19.2.4 Yes
Application cisco catalyst_sd-wan_manager 19.2.31 Yes
Application cisco catalyst_sd-wan_manager 19.2.097 Yes
Application cisco catalyst_sd-wan_manager 19.2.099 Yes
Application cisco catalyst_sd-wan_manager 19.2.929 Yes
Application cisco catalyst_sd-wan_manager 19.3.0 Yes
Application cisco catalyst_sd-wan_manager 20.1.1 Yes
Application cisco catalyst_sd-wan_manager 20.1.1.1 Yes
Application cisco catalyst_sd-wan_manager 20.1.2 Yes
Application cisco catalyst_sd-wan_manager 20.1.3 Yes
Application cisco catalyst_sd-wan_manager 20.1.12 Yes
Application cisco catalyst_sd-wan_manager 20.3.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.2 Yes
Application cisco catalyst_sd-wan_manager 20.3.2.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.3 Yes
Application cisco catalyst_sd-wan_manager 20.3.3.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.4 Yes
Application cisco catalyst_sd-wan_manager 20.3.4.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.4.2 Yes
Application cisco catalyst_sd-wan_manager 20.3.4.3 Yes
Application cisco catalyst_sd-wan_manager 20.3.5 Yes
Application cisco catalyst_sd-wan_manager 20.3.5.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.6 Yes
Application cisco catalyst_sd-wan_manager 20.3.7 Yes
Application cisco catalyst_sd-wan_manager 20.3.7.1 Yes
Application cisco catalyst_sd-wan_manager 20.3.7.2 Yes
Application cisco catalyst_sd-wan_manager 20.3.8 Yes
Application cisco catalyst_sd-wan_manager 20.4.1 Yes
Application cisco catalyst_sd-wan_manager 20.4.1.1 Yes
Application cisco catalyst_sd-wan_manager 20.4.1.2 Yes
Application cisco catalyst_sd-wan_manager 20.4.2 Yes
Application cisco catalyst_sd-wan_manager 20.4.2.1 Yes
Application cisco catalyst_sd-wan_manager 20.4.2.2 Yes
Application cisco catalyst_sd-wan_manager 20.4.2.3 Yes
Application cisco catalyst_sd-wan_manager 20.5.1 Yes
Application cisco catalyst_sd-wan_manager 20.5.1.1 Yes
Application cisco catalyst_sd-wan_manager 20.5.1.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.1.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.1.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.2.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.2.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.3 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.0.45 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.0.46 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.0.47 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.3 Yes
Application cisco catalyst_sd-wan_manager 20.6.3.4 Yes
Application cisco catalyst_sd-wan_manager 20.6.4 Yes
Application cisco catalyst_sd-wan_manager 20.6.4.0.21 Yes
Application cisco catalyst_sd-wan_manager 20.6.4.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.4.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.5 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1.7 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1.9 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1.10 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1.11 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.1.13 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.2 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.2.4 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.2.8 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.4 Yes
Application cisco catalyst_sd-wan_manager 20.6.5.5 Yes

References