CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user.

 These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content.

   There are workarounds that address this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ciscoCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
ciscosd-wan
20.3 ≤
𝑥
< 20.3.4
ciscosd-wan
20.6
ciscosd-wan
20.7
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ciscosd-wan_vmanage
17.2.6
CNA
ciscosd-wan_vmanage
17.2.7
CNA
ciscosd-wan_vmanage
17.2.8
CNA
ciscosd-wan_vmanage
17.2.9
CNA
ciscosd-wan_vmanage
17.2.10
CNA
ciscosd-wan_vmanage
17.2.4
CNA
ciscosd-wan_vmanage
17.2.5
CNA
ciscosd-wan_vmanage
18.3.1.1
CNA
ciscosd-wan_vmanage
18.3.3.1
CNA
ciscosd-wan_vmanage
18.3.3
CNA
ciscosd-wan_vmanage
18.3.4
CNA
ciscosd-wan_vmanage
18.3.5
CNA
ciscosd-wan_vmanage
18.3.7
CNA
ciscosd-wan_vmanage
18.3.8
CNA
ciscosd-wan_vmanage
18.3.6.1
CNA
ciscosd-wan_vmanage
18.3.1
CNA
ciscosd-wan_vmanage
18.3.0
CNA
ciscosd-wan_vmanage
18.4.0.1
CNA
ciscosd-wan_vmanage
18.4.3
CNA
ciscosd-wan_vmanage
18.4.302
CNA
ciscosd-wan_vmanage
18.4.303
CNA
ciscosd-wan_vmanage
18.4.4
CNA
ciscosd-wan_vmanage
18.4.5
CNA
ciscosd-wan_vmanage
18.4.0
CNA
ciscosd-wan_vmanage
18.4.1
CNA
ciscosd-wan_vmanage
18.4.6
CNA
ciscosd-wan_vmanage
19.2.0
CNA
ciscosd-wan_vmanage
19.2.97
CNA
ciscosd-wan_vmanage
19.2.99
CNA
ciscosd-wan_vmanage
19.2.1
CNA
ciscosd-wan_vmanage
19.2.2
CNA
ciscosd-wan_vmanage
19.2.3
CNA
ciscosd-wan_vmanage
19.2.31
CNA
ciscosd-wan_vmanage
19.2.929
CNA
ciscosd-wan_vmanage
19.2.4
CNA
ciscosd-wan_vmanage
20.1.1.1
CNA
ciscosd-wan_vmanage
20.1.12
CNA
ciscosd-wan_vmanage
20.1.1
CNA
ciscosd-wan_vmanage
20.1.2
CNA
ciscosd-wan_vmanage
20.1.3
CNA
ciscosd-wan_vmanage
19.3.0
CNA
ciscosd-wan_vmanage
19.1.0
CNA
ciscosd-wan_vmanage
18.2.0
CNA
ciscosd-wan_vmanage
20.3.1
CNA
ciscosd-wan_vmanage
20.3.2
CNA
ciscosd-wan_vmanage
20.3.2.1
CNA
ciscosd-wan_vmanage
20.3.3
CNA
ciscosd-wan_vmanage
20.3.3.1
CNA
ciscosd-wan_vmanage
20.4.1
CNA
ciscosd-wan_vmanage
20.4.1.1
CNA
ciscosd-wan_vmanage
20.4.1.2
CNA
ciscosd-wan_vmanage
20.4.2
CNA
ciscosd-wan_vmanage
20.4.2.2
CNA
ciscosd-wan_vmanage
20.4.2.1
CNA
ciscosd-wan_vmanage
20.4.2.3
CNA
ciscosd-wan_vmanage
20.5.1
CNA
ciscosd-wan_vmanage
20.5.1.2
CNA
ciscosd-wan_vmanage
20.5.1.1
CNA