QID 317220
Date Published: 2022-09-15
QID 317220: Cisco SD-WAN vManage Software Unauthenticated Access to Messaging Services Vulnerability (cisco-sa-vmanage-msg-serv-AqTup7vs)
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system.
QID category changed to practice as we cant add workaround in signature.
Affected Products
Prior to version 20.6.4
20.7 prior to version 20.9.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to view and inject messages into the messaging service, which can cause configuration changes or cause the system to reload.
Customers are advised to refer to cisco-sa-vmanage-msg-serv-AqTup7vs for more information.
- cisco-sa-vmanage-msg-serv-AqTup7vs -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-msg-serv-AqTup7vs
CVEs related to QID 317220
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vmanage-msg-serv-AqTup7vs |
|