CVE-2022-20747
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this vulnerability by sending a crafted API request to Cisco vManage as a lower-privileged user and gaining access to sensitive information that they would not normally be authorized to access.
Una vulnerabilidad en la API del historial del software Cisco SD-WAN vManage podría permitir a un atacante remoto autenticado acceder a información confidencial en un sistema afectado. Esta vulnerabilidad es debido a una comprobación insuficiente de la autorización de la API en el sistema operativo subyacente. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición de API diseñada a Cisco vManage como un usuario con menos privilegios y conseguir acceso a información confidencial a la que normalmente no estaría autorizado a acceder
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-02 CVE Reserved
- 2022-04-15 CVE Published
- 2024-07-05 EPSS Updated
- 2024-11-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-202: Exposure of Sensitive Information Through Data Queries
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Catalyst Sd-wan Manager Search vendor "Cisco" for product "Catalyst Sd-wan Manager" | 20.7 Search vendor "Cisco" for product "Catalyst Sd-wan Manager" and version "20.7" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Vmanage Search vendor "Cisco" for product "Sd-wan Vmanage" | < 20.6.1 Search vendor "Cisco" for product "Sd-wan Vmanage" and version " < 20.6.1" | - |
Affected
|