A vulnerability in the API endpoints for Cisco DNA Center...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 23, 2025
Description
Published by the National Vulnerability Database
Oct 6, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jul 23, 2025
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a specific API request to an affected application. A successful exploit could allow the attacker to obtain sensitive information about other users who are configured with higher privileges on the application.
References