QID 316951
Date Published: 2021-04-26
QID 316951: Cisco SD-WAN vManage XML External Entity Vulnerability(cisco-sa-vman-xml-ext-entity-q6Z7uVUg)
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated,
remote attacker to gain read and write access to information that is stored on an affected system.
Affected Products
Cisco SD-WAN vManage Software releases :
Prior to 20.1.2.21
From 20.2.0 Prior to 20.3.3.31
From 20.4.0 Prior to 20.4.1.97
From 20.5.0 Prior to 20.5.0.75
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command.
A successful exploit could allow the attacker to read and write files within the affected application.
Solution
Customers are advised to refer to cisco-sa-vman-xml-ext-entity-q6Z7uVUg for more information.
Vendor References
- cisco-sa-vman-xml-ext-entity-q6Z7uVUg -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-xml-ext-entity-q6Z7uVUg
CVEs related to QID 316951
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vman-xml-ext-entity-q6Z7uVUg |
|