PT-2021-2987 · Cisco · Cisco Sd-Wan Vmanage

Alex Lumsden

·

Published

2021-05-05

·

Updated

2023-10-16

·

CVE-2021-1508

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the Cisco SD-WAN vManage Software, which could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information. Additionally, an authenticated, local attacker could gain escalated privileges or unauthorized access to the application. The vulnerability is also associated with inadequate access control in the vManage web interface, allowing a remote attacker to potentially elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-02574
CVE-2021-1508

Affected Products

Cisco Sd-Wan Vmanage