Cisco Catalyst SD-WAN Manager 20.6.3.0.46

CPE Details

Cisco Catalyst SD-WAN Manager 20.6.3.0.46
20.6.3.0.46
2023-10-25
11h53 +00:00
2023-10-25
11h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.6.3.0.46:*:*:*:*:*:*:*

Informations

Vendor

cisco

Product

catalyst_sd-wan_manager

Version

20.6.3.0.46

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-20261 2023-10-18 16h27 +00:00 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.
6.5
Medium
CVE-2023-20262 2023-09-27 17h16 +00:00 A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected. This vulnerability is due to insufficient resource management when an affected system is in an error condition. An attacker could exploit this vulnerability by sending malicious traffic to the affected system. A successful exploit could allow the attacker to cause the SSH process to crash and restart, resulting in a DoS condition for the SSH service.
7.5
High