QID 317336
Date Published: 2023-07-13
QID 317336: Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability (cisco-sa-vmanage-unauthapi-sphCLYPA)
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
Affected Products
20.6.3.3 prior to 20.6.3.4
20.6.4 prior to 20.6.4.2
20.6.5 prior to 20.6.5.5
20.7 prior to 20.9.3.2
20.10 prior to 20.10.1.2
20.11 prior to 20.11.1.2
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance.
Customers are advised to refer to cisco-sa-vmanage-unauthapi-sphCLYPA for more information.
- cisco-sa-vmanage-unauthapi-sphCLYPA -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-unauthapi-sphCLYPA
CVEs related to QID 317336
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vmanage-unauthapi-sphCLYPA |
|