Vulnerabilities > Cisco > Catalyst SD WAN Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-18 CVE-2023-20261 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI.
network
low complexity
cisco
6.5
2023-09-27 CVE-2023-20253 Unspecified vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router device. This vulnerability is due to improper access control in the cli-management interface of an affected system.
local
low complexity
cisco
5.5
2023-08-04 CVE-2020-26065 Path Traversal vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests.
network
low complexity
cisco CWE-22
6.5
2023-05-09 CVE-2023-20098 Path Traversal vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands.
local
low complexity
cisco CWE-22
6.0
2022-10-10 CVE-2022-20830 Missing Authentication for Critical Function vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication.
network
low complexity
cisco CWE-306
5.3
2022-09-30 CVE-2022-20930 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system.
local
low complexity
cisco CWE-78
6.7
2022-05-04 CVE-2022-20734 Information Exposure vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system.
local
low complexity
cisco CWE-200
4.4
2022-04-15 CVE-2022-20735 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
6.5
2022-04-15 CVE-2022-20747 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system.
network
low complexity
cisco
6.5
2021-09-23 CVE-2021-1546 Information Exposure Through an Error Message vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information.
local
low complexity
cisco CWE-209
5.5