CVE-2023-20055
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.74%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-20055",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-20055",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-28T16:19:22.389053Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco Digital Network Architecture Center (DNA Center)",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2023-03-23T17:15:14.127",
"references": [
{
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-privesc-QFXe74RS",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-privesc-QFXe74RS",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this vulnerability by inspecting the responses from the API. Under certain circumstances, a successful exploit could allow the attacker to access the API with the privileges of a higher-level user account. To successfully exploit this vulnerability, the attacker would need at least valid Observer credentials."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la API de administración de Cisco DNA Center podría permitir que un atacante remoto autenticado eleve privilegios en el contexto de la interfaz de administración web de un dispositivo afectado. Esta vulnerabilidad se debe a la exposición involuntaria de información confidencial. Un atacante podría explotar esta vulnerabilidad inspeccionando las respuestas de la API. En determinadas circunstancias, una explotación exitosa podría permitir al atacante acceder a la API con los privilegios de una cuenta de usuario de nivel superior. Para explotar esta vulnerabilidad, el atacante necesitaría al menos credenciales de observador válidas."
}
],
"lastModified": "2026-06-17T05:29:22.477",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BE4616D-A0C4-4E43-B300-4A689EBC7FA3",
"versionEndExcluding": "2.3.3.6"
},
{
"criteria": "cpe:2.3:a:cisco:catalyst_center:2.3.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80114D6D-ADCA-48F6-B22E-1D5FBDB9BA68"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}