CVE-2023-20254

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.

 This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ciscoCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
ciscosd-wan_manager
𝑥
< 20.6.3.4
ciscosd-wan_manager
20.7 ≤
𝑥
< 20.9.3.2
ciscosd-wan_manager
20.10 ≤
𝑥
< 20.10.1.2
ciscosd-wan_manager
20.11 ≤
𝑥
< 20.11.1.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ciscocatalyst_sd-wan_manager
17.2.10 ≤
𝑥
≤ 20.9.3.1
ADP
ciscosd-wan_vmanage
17.2.6
CNA
ciscosd-wan_vmanage
17.2.7
CNA
ciscosd-wan_vmanage
17.2.8
CNA
ciscosd-wan_vmanage
17.2.9
CNA
ciscosd-wan_vmanage
17.2.10
CNA
ciscosd-wan_vmanage
17.2.4
CNA
ciscosd-wan_vmanage
17.2.5
CNA
ciscosd-wan_vmanage
18.3.1.1
CNA
ciscosd-wan_vmanage
18.3.3.1
CNA
ciscosd-wan_vmanage
18.3.3
CNA
ciscosd-wan_vmanage
18.3.4
CNA
ciscosd-wan_vmanage
18.3.5
CNA
ciscosd-wan_vmanage
18.3.7
CNA
ciscosd-wan_vmanage
18.3.8
CNA
ciscosd-wan_vmanage
18.3.6.1
CNA
ciscosd-wan_vmanage
18.3.1
CNA
ciscosd-wan_vmanage
18.3.0
CNA
ciscosd-wan_vmanage
18.4.0.1
CNA
ciscosd-wan_vmanage
18.4.3
CNA
ciscosd-wan_vmanage
18.4.302
CNA
ciscosd-wan_vmanage
18.4.303
CNA
ciscosd-wan_vmanage
18.4.4
CNA
ciscosd-wan_vmanage
18.4.5
CNA
ciscosd-wan_vmanage
18.4.0
CNA
ciscosd-wan_vmanage
18.4.1
CNA
ciscosd-wan_vmanage
18.4.6
CNA
ciscosd-wan_vmanage
19.2.0
CNA
ciscosd-wan_vmanage
19.2.97
CNA
ciscosd-wan_vmanage
19.2.99
CNA
ciscosd-wan_vmanage
19.2.1
CNA
ciscosd-wan_vmanage
19.2.2
CNA
ciscosd-wan_vmanage
19.2.3
CNA
ciscosd-wan_vmanage
19.2.31
CNA
ciscosd-wan_vmanage
19.2.929
CNA
ciscosd-wan_vmanage
19.2.4
CNA
ciscosd-wan_vmanage
20.1.1.1
CNA
ciscosd-wan_vmanage
20.1.12
CNA
ciscosd-wan_vmanage
20.1.1
CNA
ciscosd-wan_vmanage
20.1.2
CNA
ciscosd-wan_vmanage
20.1.3
CNA
ciscosd-wan_vmanage
19.3.0
CNA
ciscosd-wan_vmanage
19.1.0
CNA
ciscosd-wan_vmanage
18.2.0
CNA
ciscosd-wan_vmanage
20.3.1
CNA
ciscosd-wan_vmanage
20.3.2
CNA
ciscosd-wan_vmanage
20.3.2.1
CNA
ciscosd-wan_vmanage
20.3.3
CNA
ciscosd-wan_vmanage
20.3.3.1
CNA
ciscosd-wan_vmanage
20.3.4
CNA
ciscosd-wan_vmanage
20.3.4.1
CNA
ciscosd-wan_vmanage
20.3.4.2
CNA
ciscosd-wan_vmanage
20.3.5
CNA
ciscosd-wan_vmanage
20.3.6
CNA
ciscosd-wan_vmanage
20.3.7
CNA
ciscosd-wan_vmanage
20.3.7.1
CNA
ciscosd-wan_vmanage
20.3.4.3
CNA
ciscosd-wan_vmanage
20.3.5.1
CNA
ciscosd-wan_vmanage
20.3.7.2
CNA
ciscosd-wan_vmanage
20.4.1
CNA
ciscosd-wan_vmanage
20.4.1.1
CNA
ciscosd-wan_vmanage
20.4.1.2
CNA
ciscosd-wan_vmanage
20.4.2
CNA
ciscosd-wan_vmanage
20.4.2.2
CNA
ciscosd-wan_vmanage
20.4.2.1
CNA
ciscosd-wan_vmanage
20.4.2.3
CNA
ciscosd-wan_vmanage
20.5.1
CNA
ciscosd-wan_vmanage
20.5.1.2
CNA
ciscosd-wan_vmanage
20.5.1.1
CNA
ciscosd-wan_vmanage
20.6.1
CNA
ciscosd-wan_vmanage
20.6.1.1
CNA
ciscosd-wan_vmanage
20.6.2.1
CNA
ciscosd-wan_vmanage
20.6.2.2
CNA
ciscosd-wan_vmanage
20.6.2
CNA
ciscosd-wan_vmanage
20.6.3
CNA
ciscosd-wan_vmanage
20.6.3.1
CNA
ciscosd-wan_vmanage
20.6.1.2
CNA
ciscosd-wan_vmanage
20.6.3.2
CNA
ciscosd-wan_vmanage
20.6.3.3
CNA
ciscosd-wan_vmanage
20.6.3.0.45
CNA
ciscosd-wan_vmanage
20.6.3.0.46
CNA
ciscosd-wan_vmanage
20.6.3.0.47
CNA
ciscosd-wan_vmanage
20.7.1
CNA
ciscosd-wan_vmanage
20.7.1.1
CNA
ciscosd-wan_vmanage
20.7.2
CNA
ciscosd-wan_vmanage
20.8.1
CNA
ciscosd-wan_vmanage
20.9.1
CNA
ciscosd-wan_vmanage
20.9.2
CNA
ciscosd-wan_vmanage
20.9.2.1
CNA
ciscosd-wan_vmanage
20.9.3
CNA
ciscosd-wan_vmanage
20.9.3.1
CNA
ciscosd-wan_vmanage
20.9.2.3
CNA
ciscosd-wan_vmanage
20.9.3.0.12
CNA
ciscosd-wan_vmanage
20.9.3.0.16
CNA
ciscosd-wan_vmanage
20.9.3.0.17
CNA
ciscosd-wan_vmanage
20.9.3.0.18
CNA
ciscosd-wan_vmanage
20.9.3.0.20
CNA
ciscosd-wan_vmanage
20.9.3.0.21
CNA
ciscosd-wan_vmanage
20.9.3.0.23
CNA
ciscosd-wan_vmanage
20.10.1
CNA
ciscosd-wan_vmanage
20.10.1.1
CNA