QID 317153
Date Published: 2022-04-26
QID 317153: Cisco SD-WAN vManage Software Information Disclosure Vulnerability (cisco-sa-sdwan-vman-infodis-73sHJNEq)
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system.
Affected Products
Prior to version 20.6.1
20.7 prior to version 20.7.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
An attacker could exploit this vulnerability by sending a crafted API request to Cisco vManage as a lower-privileged user and gaining access to sensitive information that they would not normally be authorized to access.
Solution
Customers are advised to refer to cisco-sa-sdwan-vman-infodis-73sHJNEq for more information.
Vendor References
- cisco-sa-sdwan-vman-infodis-73sHJNEq -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-infodis-73sHJNEq
CVEs related to QID 317153
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vman-infodis-73sHJNEq |
|