cisco-sa-vmanage-YuTVWqy: Cisco SD-WAN vManage Software Vulnerabilities
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco SD-WAN vManage Software vulnerability?
The vulnerability ID is cisco-sa-vmanage-YuTVWqy.
What is the severity of the cisco-sa-vmanage-YuTVWqy vulnerability?
The severity of the cisco-sa-vmanage-YuTVWqy vulnerability is critical with a severity value of 9.8.
What is the affected software for the cisco-sa-vmanage-YuTVWqy vulnerability?
The affected software is Cisco SD-WAN vManage version 20.4.1, 20.3.3, and 19.2.4.
What can an unauthenticated remote attacker do with the cisco-sa-vmanage-YuTVWqy vulnerability?
An unauthenticated remote attacker can execute arbitrary code.
What can an authenticated local attacker do with the cisco-sa-vmanage-YuTVWqy vulnerability?
An authenticated local attacker can gain escalated privileges on an affected system.