Cisco Sd-Wan Solution vulnerabilities
54 known vulnerabilities affecting cisco/cisco_sd-wan_solution.
Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH43MEDIUM7
Vulnerabilities
Page 1 of 3
CVE-2021-1300P2CRITICALCVSS 9.8vn/a2021-01-20
CVE-2021-1300 [CRITICAL] CWE-119 CVE-2021-1300: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1301P2CRITICALCVSS 9.8vn/a2021-01-20
CVE-2021-1301 [CRITICAL] CWE-119 CVE-2021-1301: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1479P2CRITICALCVSS 9.8vn/a2021-04-08
CVE-2021-1479 [CRITICAL] CWE-119 CVE-2021-1479: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-1624P2HIGHCVSS 8.8≥ unspecified, < 18.4.02019-06-20
CVE-2019-1624 [HIGH] CWE-77 CVE-2019-1624: A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an aut
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted
nvd
CVE-2019-1650P2HIGHCVSS 8.8vn/a2019-01-24
CVE-2019-1650 [HIGH] CWE-20 CVE-2019-1650: A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwr
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the save
nvd
CVE-2018-15387P3CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-15387 [CRITICAL] CWE-20 CVE-2018-15387: A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypa
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to an affected device, bypassing
nvd
CVE-2021-1298P3HIGHCVSS 8.8vn/a2021-01-20
CVE-2021-1298 [HIGH] CWE-20 CVE-2021-1298: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1299P3HIGHCVSS 8.8vn/a2021-01-20
CVE-2021-1299 [HIGH] CWE-20 CVE-2021-1299: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-1651P3HIGHCVSS 8.8vn/a2019-01-24
CVE-2019-1651 [HIGH] CWE-119 CVE-2019-1651: A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote
A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affect
nvd
CVE-2019-1626P3HIGHCVSS 8.8≥ unspecified, < 18.4.02019-06-20
CVE-2019-1626 [HIGH] CWE-264 CVE-2019-1626: A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an aut
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could exploit this vulnerability by logging in
nvd
CVE-2018-0432P3HIGHCVSS 8.8vn/a2018-10-05
CVE-2018-0432 [HIGH] CWE-264 CVE-2018-0432: A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authentic
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerabil
nvd
CVE-2021-1274P3HIGHCVSS 8.6vn/a2021-01-20
CVE-2021-1274 [HIGH] CWE-119 CVE-2021-1274: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3444P3HIGHCVSS 7.5vn/a2020-11-06
CVE-2020-3444 [HIGH] CWE-20 CVE-2020-3444: A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthentic
A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristic
nvd
CVE-2019-12629P3HIGHCVSS 7.2≥ unspecified, < n/a2020-01-26
CVE-2019-12629 [HIGH] CWE-77 CVE-2019-12629: A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attac
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vuln
nvd
CVE-2021-1273P3HIGHCVSS 8.6vn/a2021-01-20
CVE-2021-1273 [HIGH] CWE-119 CVE-2021-1273: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1279P3HIGHCVSS 8.6vn/a2021-01-20
CVE-2021-1279 [HIGH] CWE-119 CVE-2021-1279: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3351P3HIGHCVSS 8.6vn/a2020-07-16
CVE-2020-3351 [HIGH] CWE-399 CVE-2020-3351: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN peering messages that are encapsulated in UDP packets. An attacker could exploit this vulnerability by sending crafted UDP messages to th
nvd
CVE-2020-3115P3HIGHCVSS 8.8≥ unspecified, < n/a2020-01-26
CVE-2020-3115 [HIGH] CWE-264 CVE-2020-3115: A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticate
A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system.
nvd
CVE-2021-1480P3HIGHCVSS 7.8vn/a2021-04-08
CVE-2021-1480 [HIGH] CWE-119 CVE-2021-1480: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1263P3HIGHCVSS 7.8vn/a2021-01-20
CVE-2021-1263 [HIGH] CWE-20 CVE-2021-1263: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
1 / 3Next →