CVE-2023-20034 is a high-severity vulnerability in the Elasticsearch database used by Cisco SD-WAN vManage software, stemming from static, hardcoded credentials. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to port 9200, gaining read access to the Elasticsearch configuration database with elasticsearch user privileges. The CVSS score is 7.5 (High), indicating network-based exploitation with low attack complexity and high confidentiality impact. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed on the KEV catalog, there is some community discussion and media coverage, suggesting awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.3, < 20.3.4CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:* | ||
20.6CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan:20.6:*:*:*:*:*:*:* | ||
20.7CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan:20.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.