CVE-2021-1546
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the local system. A successful exploit could allow the attacker to return portions of an arbitrary file, possibly resulting in the disclosure of sensitive information.
Affected (33)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 | |
| From 18.4 to 20.4.2 | |
| From 20.5 to 20.5.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vsmart Controller | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 1000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100b | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100m | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 100wm | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 2000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge 5000 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.4 to 20.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Vedge Cloud | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.