QID 316986
Date Published: 2021-07-05
QID 316986: Cisco SD-WAN vManage Information Disclosure Vulnerability(cisco-sa-sd-wan-vmanage-9VZO4gfU)
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information.
Affected Products
Cisco devices if they were running Cisco SD-WAN vManage Software releases earlier than
Release 20.4.1 and if they were operating in a multi-tenant configuration.
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to gain access to sensitive information that may include hashed credentials that could be used in future attacks.
Solution
Customers are advised to refer to cisco-sa-sd-wan-vmanage-9VZO4gfU for more information.
Vendor References
- cisco-sa-sd-wan-vmanage-9VZO4gfU -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-vmanage-9VZO4gfU
CVEs related to QID 316986
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sd-wan-vmanage-9VZO4gfU |
|