QID 317377

Date Published: 2023-10-26

QID 317377: Cisco Catalyst SD-WAN Manager Local File Inclusion Vulnerability (cisco-sa-sdwan-lfi-OWLbKUGe)

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system.

Affected Products
Earlier than 20.6.6

QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command

A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sdwan-lfi-OWLbKUGe for more information.

    CVEs related to QID 317377

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sdwan-lfi-OWLbKUGe URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-lfi-OWLbKUGe