QID 316982
Date Published: 2021-06-23
QID 316982: Cisco SD-WAN vManage Software Information Disclosure Vulnerability(cisco-sa-sdwan-vmaninfdis3-OvdR6uu8)
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software
could allow an unauthenticated, remote attacker to
view sensitive information on an affected system. To be affected by this vulnerability,
the vManage software must be in cluster mode.
Affected Products
Cisco SD-WAN vManage Software releases:
Prior to Release 20.3.1
From 20.4 Prior to 20.4.1
From 20.5 Prior to 20.5.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command.
A successful exploit could allow the attacker to view sensitive information on the affected system.
Solution
Customers are advised to refer to cisco-sa-sdwan-vmaninfdis3-OvdR6uu8 for more information.
Vendor References
- cisco-sa-sdwan-vmaninfdis3-OvdR6uu8 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmaninfdis3-OvdR6uu8
CVEs related to QID 316982
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vmaninfdis3-OvdR6uu8 |
|