Improper access control in Cisco SD-WAN vManage - CVE-2022-20696
Published: September 8, 2022
Cisco SD-WAN vManage
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the messaging server container ports. A remote attacker on the local network can view and inject messages into the messaging service, leading to configuration changes or cause the system to reload.