QID 317001
Date Published: 2021-07-22
QID 317001: Cisco SD-WAN vManage Software Information Disclosure Vulnerability(cisco-sa-sdwan-vmanage-infdis-LggOP9sE)
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software
could allow an authenticated, local attacker to read arbitrary files on the
underlying file system of an affected system.
Affected Products
Cisco SD-WAN vManage Software releases:
Prior to 20.4.2
From 20.5.0 Prior to 20.5.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to create forged authentication requests and gain unauthorized access to the web UI of an affected system.
Solution
Customers are advised to refer to cisco-sa-sdwan-vmanage-infdis-LggOP9sE for more information.
Vendor References
- cisco-sa-sdwan-vmanage-infdis-LggOP9sE -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanage-infdis-LggOP9sE
CVEs related to QID 317001
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vmanage-infdis-LggOP9sE |
|