Summary:
A vulnerability has been discovered in the Cisco SD-WAN vManage management software that can be exploited by a remote, unauthenticated attacker. This flaw grants unauthorized access to the configuration of the affected instance, allowing the attacker to read or make limited changes to the settings. Cisco SD-WAN vManage is a cloud-based solution used for managing distributed networks across multiple locations. The vulnerability tracked as CVE-2023-20214, arises from insufficient request validation in the REST API feature. By sending a specially crafted API request, an attacker can gain access to sensitive information, manipulate configurations, and disrupt network operations. It's important to note that this vulnerability only affects the REST API, not the web-based management interface or CLI. Cisco has released a security bulletin to address this critical-severity vulnerability and urges affected users to apply the necessary patches.[/subscribe_to_unlock_form]
Summary:
A vulnerability has been discovered in the Cisco SD-WAN vManage management software that can be exploited by a remote, unauthenticated attacker. This flaw grants unauthorized access to the configuration of the affected instance, allowing the attacker to read or make limited changes to the settings. Cisco SD-WAN vManage is a cloud-based solution used for managing distributed networks across multiple locations. The vulnerability tracked as CVE-2023-20214, arises from insufficient request validation in the REST API feature. By sending a specially crafted API request, an attacker can gain access to sensitive information, manipulate configurations, and disrupt network operations. It's important to note that this vulnerability only affects the REST API, not the web-based management interface or CLI. Cisco has released a security bulletin to address this critical-severity vulnerability and urges affected users to apply the necessary patches.[emaillocker id="1283"]
Recommendations:
We strongly recommend you apply an update for Cisco SD-WAN vManage releases affected by CVE-2023-20214 are:
References:
The following reports contain further technical details:
[/emaillocker]