QID 316983
Date Published: 2021-06-23
QID 316983: Cisco SD-WAN vManage Information Disclosure Vulnerability(cisco-sa-sdwan-vmanageinfdis-LKrFpbv)
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software
could allow an unauthenticated, remote attacker to view sensitive information
on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage Software must be in cluster mode.
Affected Products
Cisco SD-WAN vManage Software releases earlier than Release 20.5.1.
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to allow the attacker to view sensitive information on the affected system.
Solution
Customers are advised to refer to cisco-sa-sdwan-vmanageinfdis-LKrFpbv for more information.
Vendor References
- cisco-sa-sdwan-vmanageinfdis-LKrFpbv -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanageinfdis-LKrFpbv
CVEs related to QID 316983
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vmanageinfdis-LKrFpbv |
|