Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco DNA Center Information Disclosure Vulnerability
Vulnerability Description
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过数据查询的敏感数据暴露
Vulnerability Title
Cisco DNA Center 安全漏洞
Vulnerability Description
Cisco DNA Center是美国思科(Cisco)公司的一个网络管理和命令中心服务。 Cisco DNA Center 存在安全漏洞,该漏洞源于对 API 端点的访问控制不当。攻击者可以通过向受影响的应用程序发送特定的 API 请求来利用该漏洞。成功的利用可能允许攻击者获取有关在应用程序上配置有更高权限的其他用户的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A