CVE-2023-20179
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Sep 27, 2023
Updated: Jan 25, 2024
CWE ID 79
CWE ID 80
Summary
CVE-2023-20179 is a vulnerability affecting the web-based management interface of Cisco Catalyst SD-WAN Manager. This issue allows authenticated, remote attackers to inject malicious HTML content due to insufficient validation of user-supplied data in specific interface elements. Attackers could exploit this flaw by convincing users to visit a maliciously crafted page, leading to modified pages within the interface and potentially further browser-based attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco SD-WAN vManage
Affected Vendors
- Cisco Systems Inc