Cisco SD-WAN vManage Software Remote Code Execution Vulnerability
Published Jul 16, 2020
8.8
HIGHCVSS 3.1
EPSS 13.02%
Description
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to access the software and execute commands they should not be authorized to execute.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a |
|
- ≤ 18.3.0
- ≥ 18.4.0 · < 19.2.3
- ≥ 19.3.0 · < 20.1.1.1
Running on/with
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://packetstormsecurity.com/files/162958/Cisco-SD-WAN-vManage-19.2.2-Remote-Root.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanrce-4jtWT28P vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/162958/Cisco-SD-WAN-vManage-19.2.2-Remote-Root.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanrce-4jtWT28P | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.