Cisco Sd-Wan Vmanage vulnerabilities
61 known vulnerabilities affecting cisco/cisco_sd-wan_vmanage.
Total CVEs
61
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH18MEDIUM37
Vulnerabilities
Page 1 of 4
CVE-2020-3387P2HIGHCVSS 8.8vn/a2020-07-16
CVE-2020-3387 [HIGH] CWE-20 CVE-2020-3387: A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to ex
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage
nvd
CVE-2023-20252P2CRITICALCVSS 9.8v20.9.3.2v20.11.1.22023-09-27
CVE-2023-20252 [CRITICAL] CWE-862 CVE-2023-20252: A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manag
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user.
This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability
nvd
CVE-2020-27128P3MEDIUMCVSS 6.5vn/a2020-11-06
CVE-2020-27128 [MEDIUM] CWE-22 CVE-2020-27128: A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an au
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected a
nvd
CVE-2020-3375P2CRITICALCVSS 9.8vn/a2020-07-31
CVE-2020-3375 [CRITICAL] CWE-119 CVE-2020-3375: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to
nvd
CVE-2020-3374P2CRITICALCVSS 9.9vn/a2020-07-31
CVE-2020-3374 [CRITICAL] CWE-285 CVE-2020-3374: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availability of the affected system. The vulnerability is due to insufficient authorization checkin
nvd
CVE-2023-20214P2CRITICALCVSS 9.1v20.6.4v20.6.5+34 more2023-08-03
CVE-2023-20214 [CRITICAL] CWE-287 CVE-2023-20214: A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage so
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
This vulnerability is due to insufficient request validation when using t
nvd
CVE-2020-3592P3MEDIUMCVSS 6.5PoCvn/a2020-11-06
CVE-2020-3592 [MEDIUM] CWE-284 CVE-2020-3592: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system. The vulnerability is due to insufficient authorization checking on an affected system. An attacker could exploit this vulnerability by sending c
nvd
CVE-2021-1468P2CRITICALCVSS 9.8vn/a2021-05-06
CVE-2021-1468 [CRITICAL] CWE-20 CVE-2021-1468: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the De
nvd
CVE-2021-1225P3CRITICALCVSS 9.1vn/a2021-01-20
CVE-2021-1225 [CRITICAL] CWE-89 CVE-2021-1225: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software coul
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulne
nvd
CVE-2021-1302P3HIGHCVSS 8.8vn/a2021-01-20
CVE-2021-1302 [HIGH] CWE-20 CVE-2021-1302: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software coul
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulner
nvd
CVE-2020-3381P3HIGHCVSS 8.8vn/a2020-07-16
CVE-2020-3381 [HIGH] CWE-22 CVE-2020-3381: A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an auth
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacke
nvd
CVE-2021-1505P3HIGHCVSS 8.8vn/a2021-05-06
CVE-2021-1505 [HIGH] CWE-20 CVE-2021-1505: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1508P3HIGHCVSS 8.8vn/a2021-05-06
CVE-2021-1508 [HIGH] CWE-20 CVE-2021-1508: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2023-20254P3HIGHCVSS 8.8v17.2.6v17.2.7+98 more2023-09-27
CVE-2023-20254 [HIGH] CWE-732 CVE-2023-20254: A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant f
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.
This vulnerability is due to insu
nvd
CVE-2020-26064P3HIGHCVSS 8.1v17.2.6v17.2.7+38 more2023-08-04
CVE-2020-26064 [HIGH] CWE-611 CVE-2020-26064: A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by
nvd
CVE-2021-1284P3HIGHCVSS 8.8vn/a2021-05-06
CVE-2021-1284 [HIGH] CWE-284 CVE-2021-1284: A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. To exploit this vulnerability, the attacker must be able to access an associated Cisco SD-WAN vEdge device. This vuln
nvd
CVE-2023-20034P3HIGHCVSS 7.5v17.2.6v17.2.7+56 more2023-09-27
CVE-2023-20034 [HIGH] CWE-798 CVE-2023-20034: Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user.
These vulnerability is due to the presence of a static username and password configured on the v
nvd
CVE-2022-20696P3HIGHCVSS 8.8vn/a2022-09-08
CVE-2022-20696 [HIGH] CWE-284 CVE-2022-20696: A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists because the messaging server container ports on an affected system lack suffici
nvd
CVE-2021-1275P3HIGHCVSS 7.5vn/a2021-05-06
CVE-2021-1275 [HIGH] CWE-20 CVE-2021-1275: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1506P3HIGHCVSS 7.2vn/a2021-05-06
CVE-2021-1506 [HIGH] CWE-20 CVE-2021-1506: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
1 / 4Next →