Cisco DNA Center Privilege Escalation Vulnerability
CVE-2023-20055
8HIGH
Summary
A security flaw in the management API of Cisco DNA Center enables authenticated, remote attackers to escalate their privileges within the web-based management interface. This issue arises from the unintended disclosure of sensitive information. By examining the API responses, an attacker who possesses valid Observer credentials can potentially gain access to the API with higher-level user account privileges. As a result, this vulnerability could facilitate unauthorized actions or access within the Cisco DNA Center environment.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center)
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved