QID 317310

Date Published: 2023-03-27

QID 317310: Cisco SD-WAN vManage Software Cross-Site Request Forgery (CSRF) Vulnerability (cisco-sa-vman-csrf-76RDbLEh)

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.

Affected Products
Prior to 20.6.5
20.8 prior to 20.8.1
20.9 prior to 20.9.1

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-vman-csrf-76RDbLEh for more information.

    CVEs related to QID 317310

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-vman-csrf-76RDbLEh URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-csrf-76RDbLEh#fs