Vulnerabilities > Cisco > SD WAN

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-34726 OS Command Injection vulnerability in Cisco Sd-Wan
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device.
local
low complexity
cisco CWE-78
6.7
2021-07-22 CVE-2021-1614 Unspecified vulnerability in Cisco Sd-Wan
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory.
network
low complexity
cisco
5.3
2020-11-06 CVE-2020-3600 Incorrect Authorization vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-863
7.8
2020-11-06 CVE-2020-3595 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system.
local
low complexity
cisco CWE-732
7.8
2020-11-06 CVE-2020-3594 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-3593 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-27128 Path Traversal vulnerability in Cisco Sd-Wan
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system.
network
low complexity
cisco CWE-22
6.5
2020-10-08 CVE-2020-3536 Cross-site Scripting vulnerability in Cisco Sd-Wan
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
5.4
2020-07-31 CVE-2020-3375 Improper Input Validation vulnerability in Cisco IOS XE Sd-Wan and Sd-Wan
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device.
network
low complexity
cisco CWE-20
critical
9.8
2020-07-31 CVE-2020-3374 Incorrect Authorization vulnerability in Cisco Sd-Wan
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availability of the affected system.
network
low complexity
cisco CWE-863
critical
9.9