VYPR
Medium severity4.3NVD Advisory· Published Jun 28, 2023· Updated Jun 17, 2026

CVE-2023-20136

CVE-2023-20136

Description

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access control (RBAC) of certain OpenAPI operations. An attacker could exploit this vulnerability by issuing a crafted OpenAPI function call with valid credentials. A successful exploit could allow the attacker to execute OpenAPI operations that are reserved for the Administrator user, including the creation and deletion of user labels.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*range: <3.7.1.40
    • (no CPE)
    • (no CPE)range: 1.102.21

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.