Skip to main content

Vendor/product archive

cisco / sd-wan CVEs

Beta · best-effort

27 CVEs tagged to cisco / sd-wan3 Critical, 14 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2023-20034

Published Sep 27, 2023

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20113

Published Mar 23, 2023

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSR…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20930

Published Sep 30, 2022

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability…

CVSS 6.7 · Medium

CVE-2022-20850

Published Sep 30, 2022

A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the fi…

CVSS 5.5 · Medium

CVE-2022-20844

Published Sep 30, 2022

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34726

Published Sep 23, 2021

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the unde…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1612

Published Sep 23, 2021

A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1589

Published Sep 23, 2021

A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1614

Published Jul 22, 2021

A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to inf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3600

Published Nov 6, 2020

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3595

Published Nov 6, 2020

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3594

Published Nov 6, 2020

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3593

Published Nov 6, 2020

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27128

Published Nov 6, 2020

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3536

Published Oct 8, 2020

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3375

Published Jul 31, 2020

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to ins…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-3374

Published Jul 31, 2020

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to acce…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-3180

Published Jul 16, 2020

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static passwo…

CVSS 7.8 · High

CVE-2019-1624

Published Jun 20, 2019

A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1650

Published Jan 24, 2019

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. T…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-1648

Published Jan 24, 2019

A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vu…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-1647

Published Jan 24, 2019

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart container…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2