Cisco
Cisco Sd-wan: vulnerabilidades y CVE
Cisco Sd-wan tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-20775 | Alta (7.8) | 12% | ⚠ Explotación activa | 30 sept 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20034 | Alta (7.5) | 0.79% | — | 27 sept 2023 | Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the… |
| CVE-2023-20113 | Alta (8.1) | 0.26% | — | 23 mar 2023 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… |
| CVE-2022-20930 | Media (6.7) | 0.26% | — | 30 sept 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation.… |
| CVE-2022-20850 | Alta (7.1) | 0.21% | — | 30 sept 2022 | A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This… |
| CVE-2022-20844 | Media (5.3) | 0.92% | — | 30 sept 2022 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using… |
| CVE-2022-20818 | Alta (7.8) | 0.63% | — | 30 sept 2022 | Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the… |
| CVE-2022-20775 | Alta (7.8) | 12% | ⚠ Explotación activa | 30 sept 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI.… |
| CVE-2022-20716 | Alta (7.8) | 0.22% | — | 15 abr 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A… |
| CVE-2021-34726 | Media (6.7) | 0.37% | — | 23 sept 2021 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected… |
| CVE-2021-1612 | Alta (7.1) | 0.25% | — | 23 sept 2021 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files… |
| CVE-2021-1589 | Media (6.5) | 0.97% | — | 23 sept 2021 | A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access… |
| CVE-2021-1614 | Media (5.3) | 1.2% | — | 22 jul 2021 | A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory.… |
| CVE-2020-3600 | Alta (7.8) | 0.29% | — | 6 nov 2020 | A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient security controls on the… |
| CVE-2020-3595 | Alta (7.8) | 0.29% | — | 6 nov 2020 | A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is due to incorrect permissions being set… |
| CVE-2020-3594 | Alta (7.8) | 0.29% | — | 6 nov 2020 | A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient input validation. An… |
| CVE-2020-3593 | Alta (7.8) | 0.29% | — | 6 nov 2020 | A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient input validation. An… |
| CVE-2020-27128 | Media (6.5) | 61% | — | 6 nov 2020 | A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper… |
| CVE-2020-3536 | Media (5.4) | 0.63% | — | 8 oct 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The… |
| CVE-2020-3375 | Crítica (9.8) | 3.9% | — | 31 jul 2020 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker… |
| CVE-2020-3374 | Crítica (9.9) | 1.9% | — | 31 jul 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the… |
| CVE-2020-3180 | Alta (7.8) | 0.28% | — | 16 jul 2020 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges.… |
| CVE-2019-1624 | Alta (8.8) | 4.3% | — | 20 jun 2019 | A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is… |
| CVE-2019-1650 | Alta (8.8) | 3.5% | — | 24 ene 2019 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper… |
| CVE-2019-1648 | Alta (7.8) | 0.37% | — | 24 ene 2019 | A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to… |
| CVE-2019-1647 | Alta (8) | 0.81% | — | 24 ene 2019 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an… |
| CVE-2019-1646 | Alta (7.8) | 0.45% | — | 24 ene 2019 | A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not… |
| CVE-2018-15387 | Crítica (9.8) | 1.1% | — | 5 oct 2018 | A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.