CVE-2022-20734
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Una vulnerabilidad en el software Cisco SD-WAN vManage podría permitir a un atacante local autenticado visualizar información confidencial en un sistema afectado. Esta vulnerabilidad es debido a una insuficiencia de las restricciones del sistema de archivos. Un atacante autenticado con privilegios de netadmin podría explotar esta vulnerabilidad al acceder al vshell de un sistema afectado. Una explotación con éxito podría permitir al atacante leer información confidencial en el sistema operativo subyacente
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-02 CVE Reserved
- 2022-05-04 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Catalyst Sd-wan Manager Search vendor "Cisco" for product "Catalyst Sd-wan Manager" | >= 20.6 < 20.6.3 Search vendor "Cisco" for product "Catalyst Sd-wan Manager" and version " >= 20.6 < 20.6.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Catalyst Sd-wan Manager Search vendor "Cisco" for product "Catalyst Sd-wan Manager" | >= 20.7 < 20.7.2 Search vendor "Cisco" for product "Catalyst Sd-wan Manager" and version " >= 20.7 < 20.7.2" | - |
Affected
|