QID 317057
Date Published: 2021-09-27
QID 317057: Cisco SD-WAN vManage Software Cypher Query Language Injection Vulnerability ( cisco-sa-sd-wan-jOsuRJCc)
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system.
Affected Products
18.4 prior to 20.3.4
20.4 prior to 20.4.2
20.5 prior to 20.5.1
20.6 prior to 20.6.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to obtain sensitive information.
Solution
Customers are advised to refer to cisco-sa-sd-wan-jOsuRJCc for more information.
Vendor References
- cisco-sa-sd-wan-jOsuRJCc -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-jOsuRJCc
CVEs related to QID 317057
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sd-wan-jOsuRJCc |
|