QID 317377
Date Published: 2023-10-26
QID 317377: Cisco Catalyst SD-WAN Manager Local File Inclusion Vulnerability (cisco-sa-sdwan-lfi-OWLbKUGe)
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system.
Affected Products
Earlier than 20.6.6
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system.
Solution
Customers are advised to refer to cisco-sa-sdwan-lfi-OWLbKUGe for more information.
Vendor References
- cisco-sa-sdwan-lfi-OWLbKUGe -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-lfi-OWLbKUGe
CVEs related to QID 317377
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-lfi-OWLbKUGe |
|