PT-2021-2255 · Cisco · Cisco Sd-Wan Vmanage

Published

2021-03-03

·

Updated

2025-08-04

·

CVE-2021-1465

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco SD-WAN vManage Software (affected versions not specified)
Description: A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system. The issue is due to insufficient validation of HTTP requests, specifically HTTP requests. An attacker could exploit this by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to write arbitrary files on the affected system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-01229
CVE-2021-1465

Affected Products

Cisco Sd-Wan Vmanage