CVE-2023-20254
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled. This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.
EPSS 0.35% · 58.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco SD-WAN vManage | 18.4.303, 20.6.3.1, 18.4.5 |
| cisco | sd-wan_manager | 0, 20.7, 20.10 |
| cisco | catalyst_sd-wan_manager | 17.2.10 |
Exploit Intelligence
- cisco-sa-sdwan-vman-sc-LRLfu2z (circl)
Timeline
- Sep 27, 2023 CVE Published
- Sep 28, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 2, 2024 EPSS Score
- Feb 3, 2024 EPSS Score
- Mar 5, 2024 EPSS Score
- Apr 6, 2024 EPSS Score
- May 8, 2024 EPSS Score
- Jun 9, 2024 EPSS Score
- Jul 11, 2024 EPSS Score
- Aug 12, 2024 EPSS Score
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlre-H93FswRz advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-l2tp-dos-eB5tuFmV advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appqoe-utd-dos-p8O57p5y advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-ins-acc-con-nHAVDRBZ advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cat3k-dos-ZZA4Gb3r advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aaascp-Tyj4fEJm advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-20254 advisory