Cisco Sd-Wan Vmanage vulnerabilities
42 known vulnerabilities affecting cisco/sd-wan_vmanage.
Total CVEs
42
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH13MEDIUM24
Vulnerabilities
Page 1 of 3
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 20.3.4.1≥ 20.4, < 20.4.2.1+9 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2023-20214P2CRITICALCVSS 9.1≥ 20.10, < 20.10.1.22023-08-03
CVE-2023-20214 [CRITICAL] CWE-287 CVE-2023-20214: A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage so
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
This vulnerability is due to insufficient request validation when using t
nvd
CVE-2021-1479P2CRITICALCVSS 9.8fixed in 19.2.4≥ 19.3, < 20.3.32021-04-08
CVE-2021-1479 [CRITICAL] CWE-119 CVE-2021-1479: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3592P3MEDIUMCVSS 6.5PoC≤ 20.1.122020-11-06
CVE-2020-3592 [MEDIUM] CWE-284 CVE-2020-3592: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system. The vulnerability is due to insufficient authorization checking on an affected system. An attacker could exploit this vulnerability by sending c
nvd
CVE-2021-1468P2CRITICALCVSS 9.8fixed in 20.3.32021-05-06
CVE-2021-1468 [CRITICAL] CWE-20 CVE-2021-1468: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the De
nvd
CVE-2021-1225P3CRITICALCVSS 9.1fixed in 19.2.32021-01-20
CVE-2021-1225 [CRITICAL] CWE-89 CVE-2021-1225: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software coul
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulne
nvd
CVE-2021-1505P3HIGHCVSS 8.8fixed in 20.3.32021-05-06
CVE-2021-1505 [HIGH] CWE-20 CVE-2021-1505: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1508P3HIGHCVSS 8.8fixed in 19.2.99≥ 20.3, < 20.3.32021-05-06
CVE-2021-1508 [HIGH] CWE-20 CVE-2021-1508: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1284P3HIGHCVSS 8.8fixed in 20.3.12021-05-06
CVE-2021-1284 [HIGH] CWE-284 CVE-2021-1284: A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. To exploit this vulnerability, the attacker must be able to access an associated Cisco SD-WAN vEdge device. This vuln
nvd
CVE-2022-20696P3HIGHCVSS 8.8fixed in 20.6.42022-09-08
CVE-2022-20696 [HIGH] CWE-284 CVE-2022-20696: A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists because the messaging server container ports on an affected system lack suffici
nvd
CVE-2021-1275P3HIGHCVSS 7.5fixed in 20.3.32021-05-06
CVE-2021-1275 [HIGH] CWE-20 CVE-2021-1275: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1506P3HIGHCVSS 7.2fixed in 20.3.32021-05-06
CVE-2021-1506 [HIGH] CWE-20 CVE-2021-1506: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Detail
nvd
CVE-2021-1480P3HIGHCVSS 7.8fixed in 19.2.4≥ 19.3, < 20.3.32021-04-08
CVE-2021-1480 [HIGH] CWE-119 CVE-2021-1480: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20818P3HIGHCVSS 7.8fixed in 20.92022-09-30
CVE-2022-20818 [HIGH] CWE-25 CVE-2022-20818: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local att
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful explo
nvd
CVE-2021-1514P3HIGHCVSS 7.8fixed in 18.32021-05-06
CVE-2021-1514 [HIGH] CWE-20 CVE-2021-1514: A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could exploit this vulnerability by authenticating to
nvd
CVE-2023-20262P3HIGHCVSS 7.5fixed in 20.3.7≥ 20.10, < 20.11.1+1 more2023-09-27
CVE-2023-20262 [HIGH] CWE-399 CVE-2023-20262: A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated,
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected.
This vulnerability is due to insufficient resource
nvd
CVE-2021-1259P3MEDIUMCVSS 6.5fixed in 18.2.02021-01-20
CVE-2021-1259 [MEDIUM] CWE-22 CVE-2021-1259: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow a
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sen
nvd
CVE-2021-1137P3HIGHCVSS 7.8fixed in 19.2.4≥ 19.3, < 20.3.32021-04-08
CVE-2021-1137 [HIGH] CWE-119 CVE-2021-1137: Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote att
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20739P3HIGHCVSS 7.3fixed in 20.6.12022-04-15
CVE-2022-20739 [HIGH] CWE-269 CVE-2022-20739: A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local atta
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to exploit this vulnerability. This vulnerability exists because a file leveraged
nvd
CVE-2022-20747P3MEDIUMCVSS 6.5fixed in 20.6.12022-04-15
CVE-2022-20747 [MEDIUM] CWE-202 CVE-2022-20747: A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, re
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this vulnerability by sending a crafted API
nvd
1 / 3Next →