CVE-2022-20696
- EPSS 0.22%
- Published 08.09.2022 13:15:08
- Last modified 21.11.2024 06:43:20
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. Th...
CVE-2022-20747
- EPSS 0.41%
- Published 15.04.2022 15:15:13
- Last modified 21.11.2024 06:43:28
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on t...
CVE-2022-20739
- EPSS 0.12%
- Published 15.04.2022 15:15:13
- Last modified 21.11.2024 06:43:27
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a...
CVE-2022-20735
- EPSS 0.18%
- Published 15.04.2022 15:15:13
- Last modified 21.11.2024 06:43:26
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insuffici...
- EPSS 94.36%
- Published 10.12.2021 10:15:09
- Last modified 08.08.2025 18:52:00
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...
CVE-2021-34712
- EPSS 0.07%
- Published 23.09.2021 03:15:17
- Last modified 21.11.2024 06:11:01
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient i...
CVE-2021-1546
- EPSS 0.15%
- Published 23.09.2021 03:15:11
- Last modified 21.11.2024 05:44:35
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnera...
CVE-2021-34700
- EPSS 0.05%
- Published 22.07.2021 16:15:09
- Last modified 21.11.2024 06:10:59
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive info...
CVE-2021-1535
- EPSS 0.31%
- Published 06.05.2021 13:15:11
- Last modified 21.11.2024 05:44:34
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage S...
- EPSS 0.06%
- Published 06.05.2021 13:15:10
- Last modified 21.11.2024 05:44:31
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-suppli...