cisco-sa-sdwan-abyp-TnGFHrS: Cisco SD-WAN vManage Authorization Bypass Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-abyp-TnGFHrS
Credit
Affected Software
Event History
Frequently Asked Questions
What is the Cisco SD-WAN vManage authorization bypass vulnerability?
It is a vulnerability in the web-based management interface of Cisco SD-WAN vManage Software that allows an attacker to bypass authorization and modify the system's configuration, gain access to sensitive information, and view unauthorized information.
How can an attacker exploit this vulnerability?
An authenticated, remote attacker can exploit this vulnerability by bypassing authorization in the web-based management interface of Cisco SD-WAN vManage Software.
What is the severity of the Cisco SD-WAN vManage authorization bypass vulnerability?
The severity of this vulnerability is rated as high with a CVSS score of 8.8.
Which versions of Cisco SD-WAN vManage Software are affected?
The affected versions of Cisco SD-WAN vManage Software are 20.4.1, 20.3.2, and 19.2.4.
How can I fix the Cisco SD-WAN vManage authorization bypass vulnerability?
To fix this vulnerability, it is recommended to upgrade Cisco SD-WAN vManage Software to a version that has the necessary security patches.