QID 316950
Date Published: 2021-04-29
QID 316950: Cisco SD-WAN vManage Command Injection Vulnerability(cisco-sa-vman-cmdinj-nRHKgfHX)
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated,
remote attacker to inject arbitrary commands
on an affected system and cause a denial of service (DoS) condition.
Affected Products
Cisco SD-WAN vManage Software releases :
Prior to 20.1.2.18
From 20.2.0 Prior to 20.3.3.9
From 20.4.0 Prior to 20.4.1.97
From 20.5.0 Prior to 20.5.0.138
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command.
A successful exploit could allow the attacker to cause a DoS condition on the affected system.
Solution
Customers are advised to refer to cisco-sa-vman-cmdinj-nRHKgfHX for more information.
Vendor References
- cisco-sa-vman-cmdinj-nRHKgfHX -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX
CVEs related to QID 316950
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vman-cmdinj-nRHKgfHX |
|