« Volver al listado

Cisco

Cisco Sd-wan Firmware: vulnerabilidades y CVE

Cisco Sd-wan Firmware tiene 41 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE41
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-1241Alta (7.5)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,…
CVE-2021-1233Media (4.4)0.32%—20 ene 2021
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information on an affected device. The vulnerability is due to insufficient input validation of…
CVE-2021-1305Media (4.3)1.3%—20 ene 2021
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system,…
CVE-2021-1301Crítica (9.8)2.1%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section…
CVE-2021-1300Crítica (9.8)2.1%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section…
CVE-2021-1299Alta (8.8)2.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2021-1298Alta (8.8)2.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2021-1279Alta (8.6)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,…
CVE-2021-1278Alta (7.5)1.7%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,…
CVE-2021-1274Alta (8.6)1.9%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,…
CVE-2021-1273Alta (8.6)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,…
CVE-2021-1263Alta (7.8)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2021-1262Alta (7.8)1.3%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2021-1261Alta (7.8)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2021-1260Alta (7.8)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root…
CVE-2020-3468Media (5.4)0.99%—16 jul 2020
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists…
CVE-2020-3437Media (6.5)2.9%—16 jul 2020
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability…
CVE-2020-3406Media (5.4)0.82%—16 jul 2020
A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
CVE-2020-3405Alta (7.3)1.3%—16 jul 2020
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to…
CVE-2020-3401Media (6.5)2.6%—16 jul 2020
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an…
CVE-2020-3388Alta (7.8)0.38%—16 jul 2020
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient…
CVE-2020-3387Alta (8.8)13%—16 jul 2020
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization…
CVE-2020-3385Media (6.5)0.53%—16 jul 2020
A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The…
CVE-2020-3381Alta (8.8)2.6%—16 jul 2020
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files…
CVE-2020-3379Alta (7.8)0.34%—16 jul 2020
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input…
CVE-2020-3378Media (4.3)0.69%—16 jul 2020
A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The…
CVE-2020-3372Media (6.5)0.93%—16 jul 2020
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume excessive system memory and cause a denial of service (DoS) condition on an…
CVE-2020-3369Alta (7.5)1.4%—16 jul 2020
A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…
CVE-2020-3351Alta (8.6)1.4%—16 jul 2020
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN…
CVE-2020-3266Alta (7.8)0.56%—19 mar 2020
A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1078 Valid Accounts1
  3. T1133 External Remote Services1
  4. T1190 Exploit Public-Facing Application1
  5. T1608 Stage Capabilities1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Cisco