CVE-2023-20113
Cisco SD-WAN vManage Software Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.
| CWE | CWE-352 |
| Vendor | cisco |
| Product | cisco sd-wan vmanage |
| Ecosystems | |
| Industries | NetworkingTelecommunications |
| Published | Mar 23, 2023 |
| Last Updated | Oct 28, 2024 |
Get instant alerts for cisco cisco sd-wan vmanage
Be the first to know when new medium vulnerabilities affecting cisco cisco sd-wan vmanage are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N