CVE-2023-20179
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/09/2023
Last modified:
25/01/2024
Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content.<br />
<br />
This vulnerability is due to improper validation of user-supplied data in element fields. An attacker could exploit this vulnerability by submitting malicious content within requests and persuading a user to view a page that contains injected content. A successful exploit could allow the attacker to modify pages within the web-based management interface, possibly leading to further browser-based attacks against users of the application.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* | 20.6.6 (excluding) | |
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* | 20.7 (including) | 20.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page