Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3401


A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to the affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.


Published

2020-07-16T18:15:19.300

Last Modified

2024-11-21T05:30:57.523

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco sd-wan_firmware ≤ 19.2.2 Yes
Hardware cisco 1100-4g_integrated_services_router - No
Hardware cisco 1100-4gltegb_integrated_services_router - No
Hardware cisco 1100-4gltena_integrated_services_router - No
Hardware cisco 1100-6g_integrated_services_router - No
Hardware cisco vedge_100 - No
Hardware cisco vedge_1000 - No
Hardware cisco vedge_100b - No
Hardware cisco vedge_100m - No
Hardware cisco vedge_100wm - No
Hardware cisco vedge_2000 - No
Hardware cisco vedge_5000 - No

References