QID 317336

Date Published: 2023-07-13

QID 317336: Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability (cisco-sa-vmanage-unauthapi-sphCLYPA)

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.

Affected Products
20.6.3.3 prior to 20.6.3.4
20.6.4 prior to 20.6.4.2
20.6.5 prior to 20.6.5.5
20.7 prior to 20.9.3.2
20.10 prior to 20.10.1.2
20.11 prior to 20.11.1.2

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-vmanage-unauthapi-sphCLYPA for more information.

    CVEs related to QID 317336

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-vmanage-unauthapi-sphCLYPA URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-unauthapi-sphCLYPA