CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sd-wan:20.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sd-wan:20.7:*:*:*:*:*:*:*

History

21 Nov 2024, 07:40

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z - Patch, Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z - Patch, Vendor Advisory

03 Oct 2023, 15:52

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z - (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z - Patch, Vendor Advisory
CPE cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sd-wan:20.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sd-wan:20.6:*:*:*:*:*:*:*
First Time Cisco sd-wan
Cisco
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Sep 2023, 18:31

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-27 18:15

Updated : 2024-11-21 07:40


NVD link : CVE-2023-20034

Mitre link : CVE-2023-20034

CVE.ORG link : CVE-2023-20034


JSON object : View

Products Affected

cisco

  • sd-wan
CWE
CWE-798

Use of Hard-coded Credentials

NVD-CWE-noinfo