cisco-sa-vmanage-unauthapi-sphCLYPA: Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.This
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-vmanage-unauthapi-sphCLYPA?
The severity of cisco-sa-vmanage-unauthapi-sphCLYPA is considered critical due to the potential for unauthenticated remote access to sensitive configurations.
How do I fix cisco-sa-vmanage-unauthapi-sphCLYPA?
To fix cisco-sa-vmanage-unauthapi-sphCLYPA, update your Cisco SD-WAN vManage software to the latest patched version provided by Cisco.
Who is affected by cisco-sa-vmanage-unauthapi-sphCLYPA?
Organizations using Cisco SD-WAN vManage software versions prior to the release that mitigates the vulnerability are affected by cisco-sa-vmanage-unauthapi-sphCLYPA.
What types of access can an attacker gain through cisco-sa-vmanage-unauthapi-sphCLYPA?
An attacker can gain read permissions and limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.
Is there any workaround for cisco-sa-vmanage-unauthapi-sphCLYPA?
There are no effective workarounds for cisco-sa-vmanage-unauthapi-sphCLYPA; the recommended action is to apply the software update.