Cisco Sd-Wan Vmanage vulnerabilities
61 known vulnerabilities affecting cisco/cisco_sd-wan_vmanage.
Total CVEs
61
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH18MEDIUM37
Vulnerabilities
Page 2 of 4
CVE-2020-3405P3HIGHCVSS 7.3vn/a2020-07-16
CVE-2020-3405 [HIGH] CWE-611 CVE-2020-3405: A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by p
nvd
CVE-2020-3388P3HIGHCVSS 7.8vn/a2020-07-16
CVE-2020-3388 [HIGH] CWE-287 CVE-2020-3388: A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local atta
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI. The
nvd
CVE-2023-20262P3HIGHCVSS 7.5v17.2.6v17.2.7+73 more2023-09-27
CVE-2023-20262 [HIGH] CWE-399 CVE-2023-20262: A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated,
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected.
This vulnerability is due to insufficient resource
nvd
CVE-2020-3437P3MEDIUMCVSS 6.5vn/a2020-07-16
CVE-2020-3437 [MEDIUM] CWE-59 CVE-2020-3437: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the f
nvd
CVE-2021-1259P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1259 [MEDIUM] CWE-22 CVE-2021-1259: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sen
nvd
CVE-2020-26065P3MEDIUMCVSS 6.5v17.2.6v17.2.7+38 more2023-08-04
CVE-2020-26065 [MEDIUM] CWE-22 CVE-2020-26065: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.
The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by se
nvd
CVE-2023-20113P3HIGHCVSS 8.1vn/a2023-03-23
CVE-2023-20113 [HIGH] CWE-352 CVE-2023-20113: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could ex
nvd
CVE-2020-3180P3HIGHCVSS 7.8vn/a2020-07-16
CVE-2020-3180 [HIGH] CWE-264 CVE-2020-3180: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this v
nvd
CVE-2020-3401P3MEDIUMCVSS 6.5vn/a2020-07-16
CVE-2020-3401 [MEDIUM] CWE-22 CVE-2020-3401: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by send
nvd
CVE-2023-20261P3MEDIUMCVSS 6.5v17.2.6v17.2.7+97 more2023-10-18
CVE-2023-20261 [MEDIUM] CWE-284 CVE-2023-20261: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system.
This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and is
nvd
CVE-2022-20739P3HIGHCVSS 7.3vn/a2022-04-15
CVE-2022-20739 [HIGH] CWE-269 CVE-2022-20739: A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local atta
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to exploit this vulnerability. This vulnerability exists because a file leveraged
nvd
CVE-2021-1304P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1304 [MEDIUM] CWE-20 CVE-2021-1304: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software coul
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vuln
nvd
CVE-2021-1589P3MEDIUMCVSS 6.5vn/a2021-09-23
CVE-2021-1589 [MEDIUM] CWE-256 CVE-2021-1589: A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an aut
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending a request to an API endpoint. A su
nvd
CVE-2022-20747P3MEDIUMCVSS 6.5vn/a2022-04-15
CVE-2022-20747 [MEDIUM] CWE-202 CVE-2022-20747: A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, re
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this vulnerability by sending a crafted API
nvd
CVE-2021-1349P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1349 [MEDIUM] CWE-943 CVE-2021-1349: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by s
nvd
CVE-2021-34712P3MEDIUMCVSS 6.5vn/a2021-09-23
CVE-2021-34712 [MEDIUM] CWE-943 CVE-2021-34712: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability b
nvd
CVE-2022-20735P3MEDIUMCVSS 6.5vn/a2022-04-15
CVE-2022-20735 [MEDIUM] CWE-352 CVE-2022-20735: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could
nvd
CVE-2020-3372P4MEDIUMCVSS 6.5vn/a2020-07-16
CVE-2020-3372 [MEDIUM] CWE-400 CVE-2020-3372: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume excessive system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a
nvd
CVE-2020-27129P4MEDIUMCVSS 6.7vn/a2020-11-06
CVE-2020-27129 [MEDIUM] CWE-88 CVE-2020-27129: A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an aut
A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges. The vulnerability is due to improper validation of commands to the remote management CLI of the affected application. An attacker could exploit this vulne
nvd
CVE-2022-20930P4MEDIUMCVSS 6.7vn/a2022-09-30
CVE-2022-20930 [MEDIUM] CWE-88 CVE-2022-20930: A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands that are executed as the root user account. A successful
nvd