VYPR
Unrated severityNVD Advisory· Published Sep 23, 2021· Updated Nov 7, 2024

Cisco SD-WAN Software Information Disclosure Vulnerability

CVE-2021-1546

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the local system. A successful exploit could allow the attacker to return portions of an arbitrary file, possibly resulting in the disclosure of sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated local attacker can read arbitrary files on Cisco SD-WAN Software via a CLI command, leading to information disclosure.

Vulnerability

An authenticated, local attacker can exploit an improper file access protection mechanism in the Cisco SD-WAN Software CLI to read arbitrary files on the system. The vulnerability stems from insufficient restrictions on file access through CLI commands, allowing a user with local access to target any file on the local filesystem. Affected versions include Cisco SD-WAN Software releases 18.4, 19.2, 20.3 (fixed in 20.3.5), 20.4 (fixed in 20.4.2), 20.5 (fixed in 20.5.2), and 20.6 (fixed in 20.6.1) [1].

Exploitation

An attacker must have authenticated access to the CLI of an affected Cisco SD-WAN device. No special privileges beyond standard user-level authentication are required. The attacker simply runs a specially crafted CLI command that specifies the path to an arbitrary file on the local system, bypassing intended access controls [1].

Impact

Successful exploitation allows the attacker to read portions of any file on the local system, potentially leading to the disclosure of sensitive information such as configuration files, credentials, or other confidential data. The attacker does not gain write or execute capabilities, but the information disclosure could be leveraged for further attacks [1].

Mitigation

Cisco has released fixed software versions: 20.3.5, 20.4.2, 20.5.2, and 20.6.1. For releases 18.4 and 19.2, Cisco recommends migrating to a fixed release. Customers should consult the Cisco Security Advisory and the associated bug ID for the most current information [1]. As of publication, no workaround is listed.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.