QID 317322
Date Published: 2023-04-24
QID 317322: Cisco SD-WAN vManage Software Arbitrary File Deletion Vulnerability (cisco-sa-sdwan-vmanage-wfnqmYhN)
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files.
Affected Products
20.9 prior to 20.9.3
20.10 prior to 20.11.1
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root
Solution
Customers are advised to refer to cisco-sa-sdwan-vmanage-wfnqmYhN for more information.
Vendor References
- cisco-sa-sdwan-vmanage-wfnqmYhN -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanage-wfnqmYhN
CVEs related to QID 317322
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vmanage-wfnqmYhN |
|