Cisco Security Update – 13 July 2023

Cisco has released a security update to fix a critical vulnerability in Cisco SD-WAN vManage software.

The addressed vulnerability could allow the remote attacker to gain access, gain read permissions, or limited write permissions to the configuration, or obtain sensitive information from the affected Cisco SD-WAN vManage instance by sending a crafted API request.

Cisco SD-WAN vManage Unauthenticated REST API Access (CVE-2023-20214):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

CVE-2023-20214

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References