A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.
2020-07-16T18:15:18.907
2024-11-21T05:30:55.140
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | sd-wan_firmware | ≤ 18.3.0 | Yes |
Operating System | cisco | sd-wan_firmware | < 19.2.3 | Yes |
Operating System | cisco | sd-wan_firmware | ≤ 20.1 | Yes |
Hardware | cisco | 1100-4g_integrated_services_router | - | No |
Hardware | cisco | 1100-4gltegb_integrated_services_router | - | No |
Hardware | cisco | 1100-4gltena_integrated_services_router | - | No |
Hardware | cisco | 1100-6g_integrated_services_router | - | No |