CVE-2020-3401
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to the affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.
Affected (1)
Products: Cisco: Sd Wan Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 19.2.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco 1100 4g Integrated Services Router | All versions |
Cisco 1100 4gltegb Integrated Services Router | All versions |
Cisco 1100 4gltena Integrated Services Router | All versions |
Cisco 1100 6g Integrated Services Router | All versions |
Cisco Vedge 100 | All versions |
Cisco Vedge 1000 | All versions |
Cisco Vedge 100b | All versions |
Cisco Vedge 100m | All versions |
Cisco Vedge 100wm | All versions |
Cisco Vedge 2000 | All versions |
Cisco Vedge 5000 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.