PT-2021-1866 · Cisco · Cisco Sd-Wan

Andrew Kim

·

Published

2021-01-20

·

Updated

2023-10-06

·

CVE-2021-1298

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN products (affected versions not specified)
Description The issue concerns multiple vulnerabilities in Cisco SD-WAN products that could allow an authenticated attacker to perform command injection attacks against an affected device. This could enable the attacker to take certain actions with root privileges on the device. Specifically, the vulnerability in the vAnalytics function of the Cisco SD-WAN solution is related to insufficient input validation, which could allow a remote attacker to impact data integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-00633
CVE-2021-1298

Affected Products

Cisco Sd-Wan