Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability (CVE-2023-20214)

Published On: Mar 13, 2024 17:26

Advisory No: TZCERT/SA/2024/03/13-01

Source: Cisco

Software Affected: Cisco SD-WAN vManage software

Overview

Cisco has released security patches to address a critical vulnerability affecting Cisco SD-WAN vManage software. The vulnerability could allow an attacker to attain unauthenticated access to REST API.

Description

Cisco SD-WAN vManage is affected with an authentication vulnerability in its REST API. This is the result of insufficient request validation when using REST API feature. The vulnerability allows unauthenticated remote attackers to read or write to the configuration of the affected vManage instance.

Impact

Successful exploitation of this vulnerability may allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance.

Solution

Cisco has released patches for this vulnerability. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident