QID 317362
Date Published: 2023-09-28
QID 317362: Cisco SD-WAN vManage Authorization Bypass Vulnerability (cisco-sa-sdwan-vman-sc-LRLfu2z)
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.
Affected Products
Prior to 20.6.3.4
20.7 prior to 20.9.3.2
20.10 prior to 20.10.1.2
20.11 prior to 20.11.1.2
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to access information about another tenant, make configuration changes, or possibly take a tenant offline and cause a DoS condition.
Customers are advised to refer to cisco-sa-sdwan-vman-sc-LRLfu2z for more information.
- cisco-sa-sdwan-vman-sc-LRLfu2z -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z
CVEs related to QID 317362
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-vman-sc-LRLfu2z |
|