QID 317359

Date Published: 2023-09-28

QID 317359: Cisco SD-WAN vManage Unauthorized access Vulnerabilities (cisco-sa-sdwan-vman-sc-LRLfu2z)

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an attacker to access an affected instance or cause a denial of service (DoS) condition on an affected system.

Affected Products
20.9.3.2
20.11.1.2

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to cause the SSH process to crash and restart, resulting in a DoS condition for the SSH service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sdwan-vman-sc-LRLfu2z for more information.

    CVEs related to QID 317359

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sdwan-vman-sc-LRLfu2z URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z