cisco-sa-uabvman-SYGzt8Bv: Cisco SD-WAN vManage Software Authorization Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availability of the affected system. The vulnerability is due to insufficient authorization checking on the affected system. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to gain privileges beyond what would normally be authorized for their configured user authorization level. The attacker may be able to access sensitive information, modify the system configuration, or impact the availability of the affected system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uabvman-SYGzt8Bv
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-uabvman-SYGzt8Bv?
The cisco-sa-uabvman-SYGzt8Bv vulnerability is considered high severity as it allows an authenticated attacker to bypass authorization.
How do I fix cisco-sa-uabvman-SYGzt8Bv?
To fix cisco-sa-uabvman-SYGzt8Bv, upgrade your Cisco SD-WAN vManage Software to the latest applicable version as recommended in the advisory.
Which versions of Cisco SD-WAN vManage Software are affected by cisco-sa-uabvman-SYGzt8Bv?
The affected versions for cisco-sa-uabvman-SYGzt8Bv include versions 18.4.5, 19.2.2, and all versions from 19.3 up to 20.1, including 20.1.1.
What impact does cisco-sa-uabvman-SYGzt8Bv have on the system?
The cisco-sa-uabvman-SYGzt8Bv vulnerability could lead to unauthorized access to sensitive information and potential modifications to system configurations.
Who can be affected by cisco-sa-uabvman-SYGzt8Bv?
Organizations using Cisco SD-WAN vManage Software are at risk if they are on affected versions and have not implemented the necessary updates.