VYPR

SD-WAN vManage Software

by Cisco Systems, Inc.

CVEs (7)

  • CVE-2022-20696HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists…

  • CVE-2022-20739HigApr 15, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to…

  • CVE-2023-20113MedMar 23, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…

  • CVE-2022-20747MedApr 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating…

  • CVE-2022-20735MedApr 15, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…

  • CVE-2023-20098MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.01

    A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with…

  • CVE-2022-20734MedMay 4, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit…