QID 316985
Date Published: 2021-07-01
QID 316985: Cisco SD-WAN Software Arbitrary File Corruption Vulnerability(cisco-sa-sdwan-arbfile-7Qhd9mCn)
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system.
Affected Products
Cisco products if they are running a vulnerable release of Cisco SD-WAN software:
SD-WAN vManage Software
SD-WAN vBond Orchestrator Software
SD-WAN vEdge Cloud Routers
SD-WAN vEdge Routers
SD-WAN vManage Software
SD-WAN vSmart Controller Software
Cisco SD-WAN Software releases :
Prior to 18.4.6
From 19.2 Prior to 19.2.3
From 20.1 Prior to 20.1.2
From 20.3 Prior to 20.3.1
From 20.4 Prior to 20.4.1
From 20.5 Prior to 20.5.1
Note: Support only for SD-WAN vManage and vedge-100-M.
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to overwrite the content in any arbitrary files that reside on the underlying host file system.
Customers are advised to refer to cisco-sa-sdwan-arbfile-7Qhd9mCn for more information.
- cisco-sa-sdwan-arbfile-7Qhd9mCn -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfile-7Qhd9mCn
CVEs related to QID 316985
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-arbfile-7Qhd9mCn |
|