cisco-sa-sdwan-infodis-2-UPO232DG: Cisco SD-WAN Information Disclosure Vulnerability
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information on an affected device. The vulnerability is due to insufficient input validation of requests that are sent to the iperf tool. An attacker could exploit this vulnerability by sending a crafted request to the iperf tool, which is included in Cisco SD-WAN Software. A successful exploit could allow the attacker to obtain any file from the filesystem of an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-2-UPO232DG
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-sdwan-infodis-2-UPO232DG?
The severity of cisco-sa-sdwan-infodis-2-UPO232DG is classified as high, indicating a significant potential impact on affected systems.
How do I fix cisco-sa-sdwan-infodis-2-UPO232DG?
To fix cisco-sa-sdwan-infodis-2-UPO232DG, update your Cisco SD-WAN Software to the latest version released by Cisco.
What causes cisco-sa-sdwan-infodis-2-UPO232DG?
cisco-sa-sdwan-infodis-2-UPO232DG is caused by insufficient input validation of requests sent to the iperf tool in the CLI of Cisco SD-WAN Software.
Who is affected by cisco-sa-sdwan-infodis-2-UPO232DG?
Any organization using affected versions of Cisco SD-WAN Software is susceptible to cisco-sa-sdwan-infodis-2-UPO232DG.
Can cisco-sa-sdwan-infodis-2-UPO232DG be exploited remotely?
No, cisco-sa-sdwan-infodis-2-UPO232DG requires local authentication, meaning only authenticated local users can exploit the vulnerability.