A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25880 | A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco catalyst Center
|
|
| CPEs | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco dna Center
|
Cisco catalyst Center
|
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-06T16:30:44.907Z
Reserved: 2021-11-02T00:00:00
Link: CVE-2022-20630
Updated: 2024-08-03T02:17:52.918Z
Status : Modified
Published: 2022-02-10T18:15:08.860
Modified: 2025-07-23T15:26:38.713
Link: CVE-2022-20630
No data.
OpenCVE Enrichment
No data.
EUVD