cisco-sa-nso-auth-bypass-QnTEesp: Multiple Cisco Products Web-Based Management Interface Privilege Escalation Vulnerability
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-nso-auth-bypass-QnTEesp?
The severity of cisco-sa-nso-auth-bypass-QnTEesp is categorized as high.
How do I fix cisco-sa-nso-auth-bypass-QnTEesp?
To fix cisco-sa-nso-auth-bypass-QnTEesp, apply the latest security patch released by Cisco for affected products.
Who is affected by cisco-sa-nso-auth-bypass-QnTEesp?
Cisco Crosswork Network Services Orchestrator, Cisco ConfD, Cisco Optical Site Manager, and Cisco RV340 Dual WAN Gigabit VPN Router users are affected by cisco-sa-nso-auth-bypass-QnTEesp.
What type of attack does cisco-sa-nso-auth-bypass-QnTEesp address?
cisco-sa-nso-auth-bypass-QnTEesp addresses an authenticated remote attack exploit via the JSON-RPC API.
Is there a workaround for cisco-sa-nso-auth-bypass-QnTEesp?
There are no official workarounds for cisco-sa-nso-auth-bypass-QnTEesp; updating to the latest version is recommended.