SB2022092932 - Missing Authentication for Critical Function in Cisco vManage
Published: September 29, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authentication for Critical Function (CVE-ID: CVE-2022-20830)
The vulnerability allows a remote attacker to compromsie the target system.
The vulnerability exists due to an error in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC). A remote attacker can access the exposed GUI of Cisco SD-AVC and gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.