CVE-2024-20333

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
27/03/2024
Last modified:
23/07/2025

Description

A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device.<br /> <br /> This vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to change a specific field within the web-based management interface, even though they should not have access to change that field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* 2.3.5.4 (excluding)