Vulnerability Name: | CVE-2022-20939 (CCN-237824) | ||||||
Assigned: | 2021-11-02 | ||||||
Published: | 2022-10-05 | ||||||
Updated: | 2022-10-05 | ||||||
Summary: | Cisco Smart Software Manager On-Prem could allow a remote authenticated attacker to gain elevated privileges on the system, caused by inadequate protection of sensitive user information. By accessing certain logs on an affected system, an attacker could exploit this vulnerability to use the obtained information to elevate privileges to System Admin. | ||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||
CVSS v2 Severity: | 4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: MITRE Type: CNA CVE-2022-20939 Source: XF Type: UNKNOWN cisco-smartsoftware-cve202220939-priv-esc(237824) Source: CCN Type: Cisco Security Advisory cisco-sa-cssm-priv-esc-SEjz69dv Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |