CVE Vulnerabilities

CVE-2021-1468

Improper Authentication

Published: May 06, 2021 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Catalyst_sd-wan_manager Cisco 20.4 (including) 20.4.1 (excluding)
Catalyst_sd-wan_manager Cisco 20.5 (including) 20.5.1 (excluding)
Sd-wan_vmanage Cisco * 20.3.3 (excluding)

Potential Mitigations

References