QID 317002

Date Published: 2021-07-22

QID 317002: Cisco SD-WAN Software Information Disclosure Vulnerability(cisco-sa-sdw-mpls-infodisclos-MSSRFkZq)

A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software
could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory.

Affected Products
Cisco SD-WAN Software following releases:
From 18.4 Prior to 18.4.6
From 19.2 Prior to 19.2.3
From 20.3 Prior to 20.3.2
From 20.4 Prior to 20.4.1
From 20.5 Prior to 20.5.1
Note: Support only for Cisco SD-WAN vmanage and vedge-100-M models.

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to gain unauthorized access to sensitive information.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sdw-mpls-infodisclos-MSSRFkZq for more information.

    CVEs related to QID 317002

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sdw-mpls-infodisclos-MSSRFkZq URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-mpls-infodisclos-MSSRFkZq