TL;DR π
A medium-severity vulnerability has been identified in the Cisco Secure Network Analytics Manager API, which could allow authenticated low-privileged users to generate fraudulent findings. Cisco has released updates to address this issue, but no workarounds are available.
What happened π΅οΈββοΈ
A vulnerability in the API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to create fraudulent findings. This vulnerability arises from insufficient authorization enforcement on a specific API. An attacker could exploit this by authenticating as a low-privileged user and making crafted API calls, potentially obfuscating legitimate findings in analytics reports or generating false alarms and alerts.