QID 316952
Date Published: 2021-04-26
QID 316952: Cisco SD-WAN vManage Authorization Bypass Vulnerability(cisco-sa-vman-auth-bypass-Z3Zze5XC)
A vulnerability in the web-based management interface of Cisco SD-WAN vManage
Software could allow an authenticated, remote attacker to
bypass authorization checking and gain access to sensitive information on an affected system.
Affected Products
Cisco SD-WAN vManage Software releases :
Prior to 20.1.2.15
From 20.2.0 Prior to 20.3.3.5
From 20.4.0 Prior to 20.4.1.67
From 20.5.0 Prior to 20.5.0.48
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command.
A successful exploit could allow the attacker to bypass authorization checking and gain access to sensitive information on the affected system.
Customers are advised to refer to cisco-sa-vman-auth-bypass-Z3Zze5XC for more information.
- cisco-sa-vman-auth-bypass-Z3Zze5XC -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-auth-bypass-Z3Zze5XC
CVEs related to QID 316952
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vman-auth-bypass-Z3Zze5XC |
|