Cisco Sd-Wan Solution vulnerabilities

54 known vulnerabilities affecting cisco/cisco_sd-wan_solution.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH43MEDIUM7

Vulnerabilities

Page 3 of 3
CVE-2019-12619MEDIUMCVSS 6.5≥ unspecified, < n/a2020-01-26
CVE-2019-12619 [MEDIUM] CWE-89 CVE-2019-12619: A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that in
cvelistv5nvd
CVE-2019-1951MEDIUMCVSS 5.8≥ unspecified, < 19.1.02019-08-08
CVE-2019-1951 [MEDIUM] CWE-20 CVE-2019-1951: A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthentic A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characterist
cvelistv5nvd
CVE-2019-1625HIGHCVSS 7.8≥ unspecified, < 18.3.62019-06-20
CVE-2019-1625 [HIGH] CWE-264 CVE-2019-1625: A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user on an affected device. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that cou
cvelistv5nvd
CVE-2019-1624HIGHCVSS 8.8≥ unspecified, < 18.4.02019-06-20
CVE-2019-1624 [HIGH] CWE-77 CVE-2019-1624: A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an aut A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted
cvelistv5nvd
CVE-2019-1626HIGHCVSS 8.8≥ unspecified, < 18.4.02019-06-20
CVE-2019-1626 [HIGH] CWE-264 CVE-2019-1626: A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an aut A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could exploit this vulnerability by logging in
cvelistv5nvd
CVE-2019-1651HIGHCVSS 8.8vn/a2019-01-24
CVE-2019-1651 [HIGH] CWE-119 CVE-2019-1651: A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affect
cvelistv5nvd
CVE-2019-1648HIGHCVSS 7.8vn/a2019-01-24
CVE-2019-1648 [HIGH] CWE-264 CVE-2019-1648: A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenti A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a craft
cvelistv5nvd
CVE-2019-1650HIGHCVSS 8.8vn/a2019-01-24
CVE-2019-1650 [HIGH] CWE-20 CVE-2019-1650: A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwr A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the save
cvelistv5nvd
CVE-2019-1646HIGHCVSS 7.8vn/a2019-01-24
CVE-2019-1646 [HIGH] CWE-264 CVE-2019-1646: A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local at A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by sending crafted commands to the CLI
cvelistv5nvd
CVE-2019-1647HIGHCVSS 8.0vn/a2019-01-24
CVE-2019-1647 [HIGH] CWE-284 CVE-2019-1647: A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypa A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed serv
cvelistv5nvd
CVE-2018-15387CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-15387 [CRITICAL] CWE-20 CVE-2018-15387: A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypa A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to an affected device, bypassing
cvelistv5nvd
CVE-2018-0433HIGHCVSS 7.8vn/a2018-10-05
CVE-2018-0433 [HIGH] CWE-77 CVE-2018-0433: A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an auth A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted in
cvelistv5nvd
CVE-2018-0434HIGHCVSS 7.4vn/a2018-10-05
CVE-2018-0434 [HIGH] CWE-295 CVE-2018-0434: A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an u A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supply
cvelistv5nvd
CVE-2018-0432HIGHCVSS 8.8vn/a2018-10-05
CVE-2018-0432 [HIGH] CWE-264 CVE-2018-0432: A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authentic A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerabil
cvelistv5nvd