CVE-2023-20183 describes multiple vulnerabilities in the API of Cisco DNA Center Software, affecting Cisco Catalyst Center. An authenticated, remote attacker could exploit these flaws to read restricted container information, enumerate user data, or execute arbitrary commands as root within a restricted container. With a CVSS score of 4.3 (Medium), the attack requires authentication but has low complexity, potentially leading to information disclosure or limited command execution. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.3.7CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* | ||
>= 2.3.4, < 2.3.5.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.