QID 317058

Date Published: 2021-09-24

QID 317058: Cisco SD-WAN vManage Software Disaster Recovery Feature Password Exposure Vulnerability ( cisco-sa-sd-wan-credentials-ydYfskzZ)

A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials.

Affected Products
Cisco SD-WAN vManage Software releases:
20.3 prior to 20.3.4
20.4 prior to 20.4.2
20.5 prior to 20.5.2
20.6 prior to 20.6.1

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to gain unauthorized access to administrative credentials that could be used in further attacks.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sd-wan-credentials-ydYfskzZ for more information.

    CVEs related to QID 317058

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sd-wan-credentials-ydYfskzZ URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-credentials-ydYfskzZ