CVE-2022-20939

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2024
Last modified:
31/07/2025

Description

A vulnerability in the web-based management interface of Cisco&amp;nbsp;Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system.<br /> This vulnerability is due to inadequate protection of sensitive user information. An attacker could exploit this vulnerability by accessing certain logs on an affected system. A successful exploit could allow the attacker to use the obtained information to elevate privileges to System Admin.Cisco&amp;nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* 8-202206 (excluding)
cpe:2.3:a:cisco:smart_software_manager_satellite:*:*:*:*:*:*:*:* 6.3.0 (including)