Vulnerabilities > Cisco > IOS XE SD WAN > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-34724 Unspecified vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user.
local
low complexity
cisco
6.0
2021-09-23 CVE-2021-34725 OS Command Injection vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34729 OS Command Injection vulnerability in Cisco IOS XE and IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2021-03-24 CVE-2021-1371 Improper Privilege Management vulnerability in Cisco IOS XE Sd-Wan 17.2.0
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration.
low complexity
cisco CWE-269
6.6
2021-03-24 CVE-2021-1454 Argument Injection or Modification vulnerability in Cisco IOS XE and IOS XE Sd-Wan
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges.
local
low complexity
cisco CWE-88
6.7
2021-03-24 CVE-2021-1383 Argument Injection or Modification vulnerability in Cisco IOS XE
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges.
local
low complexity
cisco CWE-88
6.7
2021-01-20 CVE-2021-1305 Incorrect Authorization vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access.
network
low complexity
cisco CWE-863
4.3
2020-06-03 CVE-2020-3216 Improper Authentication vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device.
low complexity
cisco CWE-287
6.8