PT-2020-3112 · Cisco · Cisco Sd-Wan Vmanage

Published

2020-07-15

·

Updated

2023-05-23

·

CVE-2020-3381

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue is related to a lack of proper validation of files uploaded to an affected device, allowing an authenticated, remote attacker to conduct directory traversal attacks. This could provide read and write access to sensitive files on a targeted system. An attacker could exploit this by uploading a crafted file to an affected system, potentially allowing them to view or modify arbitrary files.
Recommendations For Cisco SD-WAN vManage Software, consider restricting access to the file upload feature until a proper fix is applied. As a temporary workaround, consider implementing additional validation for uploaded files to prevent directory traversal attacks. Avoid using the file upload feature in the web management interface until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2020-03404
CVE-2020-3381

Affected Products

Cisco Sd-Wan Vmanage