CVE-2022-20939
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2024
Last modified:
31/07/2025
Description
A vulnerability in the web-based management interface of Cisco&nbsp;Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system.<br />
This vulnerability is due to inadequate protection of sensitive user information. An attacker could exploit this vulnerability by accessing certain logs on an affected system. A successful exploit could allow the attacker to use the obtained information to elevate privileges to System Admin.Cisco&nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* | 8-202206 (excluding) | |
| cpe:2.3:a:cisco:smart_software_manager_satellite:*:*:*:*:*:*:*:* | 6.3.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



