CVE-2023-20113

CVSS V2 None CVSS V3 None
Description
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.
Overview
  • CVE ID
  • CVE-2023-20113
  • Assigner
  • ykramarz@cisco.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-23T17:15:15
  • Last Modified Date
  • 2023-04-03T13:35:41
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:* 1 OR 20.6.5
cpe:2.3:a:cisco:sd-wan:20.8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan:20.9.0:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 03:16:27 Added to TrackCVE
2023-04-17 03:16:29 Weakness Enumeration new
2023-04-17 04:54:16 CVSS V3 information new