CVE-2023-20899: High severity vmware nsx sd-wan vulnerability
Published Jul 6, 2023
·Updated
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.
Affected Software
2 affected components
VMware Sd-wan Edge Firmware>=4.5.0<4.5.2
VMware SD-WAN Edge
Event History
Jul 6, 2023
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20899?
CVE-2023-20899 is a vulnerability in VMware SD-WAN (Edge) that allows an unauthenticated attacker to bypass authentication and download the Diagnostic bundle of the application.
2
What is the severity of CVE-2023-20899?
The severity of CVE-2023-20899 is high, with a CVSS score of 7.5.
3
What software is affected by CVE-2023-20899?
Vmware SD-wan Edge Firmware versions 4.5.0 to 4.5.2 are affected by CVE-2023-20899.
4
How can an unauthenticated attacker exploit CVE-2023-20899?
An unauthenticated attacker can exploit CVE-2023-20899 by downloading the Diagnostic bundle of the application under VMware SD-WAN Management.
5
Is VMware SD-WAN Edge vulnerable to CVE-2023-20899?
No, VMware SD-WAN Edge is not vulnerable to CVE-2023-20899.