VYPR
Unrated severityNVD Advisory· Published May 18, 2023· Updated Oct 25, 2024

Cisco DNA Center Software API Vulnerabilities

CVE-2023-20183

Description

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple API vulnerabilities in Cisco DNA Center Software allow authenticated remote attackers to read data, enumerate users, or execute commands as root.

Vulnerability

Multiple vulnerabilities exist in the API of Cisco DNA Center Software, allowing an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. These vulnerabilities are due to insufficient validation of user-supplied input in API requests. Affected versions include Cisco DNA Center Software releases prior to the fixed versions specified in the advisory [1].

Exploitation

An attacker must have valid authentication credentials to the Cisco DNA Center API. Exploitation does not require additional privileges beyond those of an authenticated user. By sending specially crafted API requests, the attacker can trigger the vulnerabilities. The vulnerabilities are not interdependent; exploitation of one does not require another [1].

Impact

Successful exploitation can lead to different outcomes depending on the vulnerability exploited. An attacker can read sensitive information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. This could result in full compromise of the affected system [1].

Mitigation

Cisco has released software updates that address these vulnerabilities. The fixed versions are detailed in the Cisco Security Advisory [1]. There are no workarounds that address these vulnerabilities. Users should upgrade to the appropriate fixed release as soon as possible.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.