PT-2021-2985 · Cisco · Cisco Sd-Wan Vmanage

Alex Lumsden

·

Published

2021-05-05

·

Updated

2023-10-16

·

CVE-2021-1505

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the Cisco SD-WAN vManage Software, which could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information. It could also allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. The vulnerability is associated with privilege management errors in the vManage web interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-02572
CVE-2021-1505

Affected Products

Cisco Sd-Wan Vmanage