Cisco SD-WAN vManage Software是美国思科(Cisco)公司的一款用于SD-WAN(软件定义广域网络)解决方案的管理软件。 Cisco SD-WAN vManage Software 中的web-based management interface 存在跨站脚本漏洞,成功的利用该漏洞可能使攻击者能够在上下文中执行任意脚本代码或者获取一些敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-3603 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3600 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3595 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3594 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3593 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3604 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3573 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3574 | 7.5 HIGH | Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability |
| CVE-2020-3556 | 7.3 HIGH | Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability |
| CVE-2020-3588 | 7.3 HIGH | Cisco Webex Meetings Desktop App Arbitrary Code Execution Vulnerability |
| CVE-2020-27129 | 6.7 MEDIUM | Cisco SD-WAN vManage Software Command Injection Vulnerability |
| CVE-2020-3592 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Authorization Bypass Vulnerability |
| CVE-2020-26084 | 6.5 MEDIUM | Cisco Edge Fog Fabric Resource Exposure Vulnerability |
| CVE-2020-27128 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability |
| CVE-2020-3587 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3590 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3371 | 6.3 MEDIUM | Cisco Integrated Management Controller Command Injection Vulnerability |
| CVE-2020-3551 | 6.1 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
| CVE-2020-27123 | 5.5 MEDIUM | Cisco AnyConnect Secure Mobility Client for Windows Arbitrary File Read Vulnerability |
| CVE-2020-26083 | 4.8 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet