Description
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24238 | A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files. |
References
History
Wed, 23 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco catalyst Center
|
|
| CPEs | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco dna Center
|
Cisco catalyst Center
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-10-25T16:02:49.507Z
Reserved: 2022-10-27T00:00:00.000Z
Link: CVE-2023-20059
No data.
Status : Modified
Published: 2023-03-23T17:15:14.303
Modified: 2025-07-23T15:26:38.713
Link: CVE-2023-20059
No data.
OpenCVE Enrichment
No data.
EUVD