QID 317374
Date Published: 2023-10-17
QID 317374: Cisco Catalyst SD-WAN Manager Web UI HTML Injection Vulnerability (cisco-sa-vmanage-html-3ZKh8d6x)
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content.
Affected Products
Earlier than 20.6.6
20.7 Migrate to a fixed release.
20.8 Migrate to a fixed release.
20.9 Migrate to a fixed release.
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
NOTE: This QID is marked as practice because we cannot check multi-tenant mode if enabled.
A successful exploit could allow allow an authenticated, remote attacker to inject HTML content.
Solution
Customers are advised to refer to cisco-sa-vmanage-html-3ZKh8d6x for more information.
Vendor References
- cisco-sa-vmanage-html-3ZKh8d6x -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-html-3ZKh8d6x
CVEs related to QID 317374
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-vmanage-html-3ZKh8d6x |
|