QID 317002
Date Published: 2021-07-22
QID 317002: Cisco SD-WAN Software Information Disclosure Vulnerability(cisco-sa-sdw-mpls-infodisclos-MSSRFkZq)
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software
could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory.
Affected Products
Cisco SD-WAN Software following releases:
From 18.4 Prior to 18.4.6
From 19.2 Prior to 19.2.3
From 20.3 Prior to 20.3.2
From 20.4 Prior to 20.4.1
From 20.5 Prior to 20.5.1
Note: Support only for Cisco SD-WAN vmanage and vedge-100-M models.
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to gain unauthorized access to sensitive information.
Customers are advised to refer to cisco-sa-sdw-mpls-infodisclos-MSSRFkZq for more information.
- cisco-sa-sdw-mpls-infodisclos-MSSRFkZq -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-mpls-infodisclos-MSSRFkZq
CVEs related to QID 317002
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdw-mpls-infodisclos-MSSRFkZq |
|