CVE-2022-20830

MEDIUM

Cisco Catalyst SD-WAN Manager 20.4-20.6.1 and SD-WAN vManage 18.4-20.3.4.1 - Unauthenticated GUI Access via SD-AVC

Title source: llm
STIX 2.1

Description

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow the attacker to view managed device names, SD-AVC logs, and SD-AVC DNS server IP addresses.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
cisco/catalyst_sd-wan_manager 20.7
cisco/catalyst_sd-wan_manager 20.4 - 20.6.1
cisco/sd-wan_vmanage 18.4 - 20.3.4.1
Published Oct 10, 2022
Tracked Since Feb 18, 2026