CVE-2023-20059 is a medium-severity vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center, affecting Cisco Catalyst Center. It allows an authenticated, low-privileged remote attacker to view sensitive information, such as configuration files, in clear text due to improper role-based access control (RBAC). The attack requires valid user credentials and involves querying an internal API. While the CVSS score is 6.5, indicating a moderate risk, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.3.7CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* | ||
>= 2.3.4.0, < 2.3.5.0CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.