CVE-2023-20179

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/09/2023
Last modified:
25/01/2024

Description

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content.<br /> <br /> This vulnerability is due to improper validation of user-supplied data in element fields. An attacker could exploit this vulnerability by submitting malicious content within requests and persuading a user to view a page that contains injected content. A successful exploit could allow the attacker to modify pages within the web-based management interface, possibly leading to further browser-based attacks against users of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 20.6.6 (excluding)
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 20.7 (including) 20.10 (excluding)