CyberRota Analysis
AI-GeneratedThe vulnerability in Cisco Catalyst SD-WAN Manager's web-based management interface allows authenticated, low-privileged attackers to access sensitive information in clear text due to inadequate access control for certain template types. This could lead to the exposure of authentication credentials, potentially compromising network infrastructure and connected services. Organizations using Cisco SD-WAN Manager should prioritize remediation to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.