QID 317059

Date Published: 2021-09-27

QID 317059: Cisco SD-WAN Software Information Disclosure Vulnerability ( cisco-sa-sd-wan-Fhqh8pKX)

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information.

Affected Products
18.4 prior to 20.4.2
20.5 prior to 20.5.2
20.6 prior to 20.6.1

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to return portions of an arbitrary file, possibly resulting in the disclosure of sensitive information.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sd-wan-Fhqh8pKX for more information.

    CVEs related to QID 317059

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sd-wan-Fhqh8pKX URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-Fhqh8pKX