QID 317148
Date Published: 2022-04-19
QID 317148: Cisco SD-WAN Solution Improper Access Control Vulnerability (cisco-sa-sd-wan-file-access-VW36d28P)
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges.
Affected Products
Cisco SD-WAN 20.6
Cisco SD-WAN 20.7
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device. If successful, the attacker could gain escalated privileges and take actions on the system with the privileges of the root user.
Solution
Customers are advised to refer to
cisco-sa-sd-wan-file-access-VW36d28P for more information.
Vendor References
- cisco-sa-sd-wan-file-access-VW36d28P -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-file-access-VW36d28P
CVEs related to QID 317148
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sd-wan-file-access-VW36d28P |
|