Cisco Sd-Wan Firmware vulnerabilities
41 known vulnerabilities affecting cisco/sd-wan_firmware.
Total CVEs
41
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM13
Vulnerabilities
Page 1 of 3
CVE-2019-16012P2HIGHCVSS 8.1fixed in 19.2.22020-03-19
CVE-2019-16012 [HIGH] CWE-77 CVE-2019-16012: A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious
nvd
CVE-2020-3387P2HIGHCVSS 8.8≤ 18.3.0≥ 18.4.0, < 19.2.3+1 more2020-07-16
CVE-2020-3387 [HIGH] CWE-20 CVE-2020-3387: A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to ex
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage
nvd
CVE-2021-1300P2CRITICALCVSS 9.8v18.3.8v18.4.4+2 more2021-01-20
CVE-2021-1300 [CRITICAL] CWE-119 CVE-2021-1300: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1301P2CRITICALCVSS 9.8v18.3.8v18.4.4+2 more2021-01-20
CVE-2021-1301 [CRITICAL] CWE-119 CVE-2021-1301: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1298P3HIGHCVSS 8.8v18.2.0v18.3.0+5 more2021-01-20
CVE-2021-1298 [HIGH] CWE-20 CVE-2021-1298: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1299P3HIGHCVSS 8.8v18.2.0v18.3.0+5 more2021-01-20
CVE-2021-1299 [HIGH] CWE-20 CVE-2021-1299: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3381P3HIGHCVSS 8.8≤ 18.3.0≥ 18.4.0, < 19.2.3+1 more2020-07-16
CVE-2020-3381 [HIGH] CWE-22 CVE-2020-3381: A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an auth
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacke
nvd
CVE-2019-1626P3HIGHCVSS 8.8≤ 18.3.62019-06-20
CVE-2019-1626 [HIGH] CWE-264 CVE-2019-1626: A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an aut
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could exploit this vulnerability by logging in
nvd
CVE-2021-1274P3HIGHCVSS 8.6v18.3.5v18.3.8+8 more2021-01-20
CVE-2021-1274 [HIGH] CWE-119 CVE-2021-1274: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-12629P3HIGHCVSS 7.2fixed in 18.3.02020-01-26
CVE-2019-12629 [HIGH] CWE-77 CVE-2019-12629: A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attac
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vuln
nvd
CVE-2021-1273P3HIGHCVSS 8.6v18.3.5v18.3.8+8 more2021-01-20
CVE-2021-1273 [HIGH] CWE-119 CVE-2021-1273: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1279P3HIGHCVSS 8.6v18.3.5v18.3.8+8 more2021-01-20
CVE-2021-1279 [HIGH] CWE-119 CVE-2021-1279: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3351P3HIGHCVSS 8.6fixed in 17.2.7≥ 17.2.8, < 18.3.02020-07-16
CVE-2020-3351 [HIGH] CWE-399 CVE-2020-3351: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN peering messages that are encapsulated in UDP packets. An attacker could exploit this vulnerability by sending crafted UDP messages to th
nvd
CVE-2020-3115P3HIGHCVSS 8.8v18.4.1v19.1.02020-01-26
CVE-2020-3115 [HIGH] CWE-264 CVE-2020-3115: A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticate
A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system.
nvd
CVE-2021-1263P3HIGHCVSS 7.8v18.2.0v18.3.0+5 more2021-01-20
CVE-2021-1263 [HIGH] CWE-20 CVE-2021-1263: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1260P3HIGHCVSS 7.8v18.2.0v18.3.0+5 more2021-01-20
CVE-2021-1260 [HIGH] CWE-20 CVE-2021-1260: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1261P3HIGHCVSS 7.8v18.2.0v18.3.0+5 more2021-01-20
CVE-2021-1261 [HIGH] CWE-20 CVE-2021-1261: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1262P3HIGHCVSS 7.8fixed in 19.2.4≥ 19.3.0, < 20.1.2+2 more2021-01-20
CVE-2021-1262 [HIGH] CWE-20 CVE-2021-1262: Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform c
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3405P3HIGHCVSS 7.3≤ 19.2.22020-07-16
CVE-2020-3405 [HIGH] CWE-611 CVE-2020-3405: A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by p
nvd
CVE-2021-1278P3HIGHCVSS 7.5v18.3.5v18.3.8+8 more2021-01-20
CVE-2021-1278 [HIGH] CWE-119 CVE-2021-1278: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
1 / 3Next →