CVE-2021-1480: Cisco SD-WAN vManage Software Vulnerabilities
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco SD-WAN vManage Software vulnerability?
The vulnerability ID is CVE-2021-1480.
What is the severity of CVE-2021-1480?
The severity of CVE-2021-1480 is high with a CVSS score of 7.8.
What is the affected software of CVE-2021-1480?
The affected software is Cisco Catalyst SD-WAN Manager version 20.4.1 and below, and Cisco SD-WAN vManage versions 19.2.4, 19.3, and 20.3.3.
What are the potential consequences of CVE-2021-1480?
An unauthenticated remote attacker could execute arbitrary code, and an authenticated local attacker could gain escalated privileges on an affected system.
How do I fix CVE-2021-1480?
Cisco has released software updates to address this vulnerability. It is recommended to upgrade to the latest version of Cisco SD-WAN vManage Software.