Cisco DNA Center Privilege Escalation Vulnerability
CVE-2023-20055

8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
23 March 2023

Badges

👾 Exploit Exists

Summary

A security flaw in the management API of Cisco DNA Center enables authenticated, remote attackers to escalate their privileges within the web-based management interface. This issue arises from the unintended disclosure of sensitive information. By examining the API responses, an attacker who possesses valid Observer credentials can potentially gain access to the API with higher-level user account privileges. As a result, this vulnerability could facilitate unauthorized actions or access within the Cisco DNA Center environment.

Affected Version(s)

Cisco Digital Network Architecture Center (DNA Center)

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.