Vulnerabilities > Cisco > Catalyst SD WAN Manager

DATE CVE VULNERABILITY TITLE RISK
2022-09-30 CVE-2022-20775 Path Traversal vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
local
low complexity
cisco CWE-22
7.8
2022-09-30 CVE-2022-20930 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system.
local
low complexity
cisco CWE-78
6.7
2022-09-08 CVE-2022-20696 Unspecified vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system.
low complexity
cisco
8.8
2022-05-04 CVE-2022-20734 Information Exposure vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system.
local
low complexity
cisco CWE-200
4.4
2022-04-15 CVE-2022-20716 Unspecified vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges.
local
low complexity
cisco
7.8
2022-04-15 CVE-2022-20735 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
6.5
2022-04-15 CVE-2022-20739 Improper Privilege Management vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user.
local
low complexity
cisco CWE-269
7.3
2022-04-15 CVE-2022-20747 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system.
network
low complexity
cisco
6.5
2021-09-23 CVE-2021-1546 Information Exposure Through an Error Message vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information.
local
low complexity
cisco CWE-209
5.5
2021-09-23 CVE-2021-34712 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system.
network
low complexity
cisco
6.5