Cisco SD-WAN vManage Software是美国思科(Cisco)公司的一款用于SD-WAN(软件定义广域网络)解决方案的管理软件。 Cisco SD-WAN vManage Software 存在安全漏洞,该漏洞源于当低权限用户在受影响的系统上运行特定命令时会执行由 root 用户利用的文件。攻击者利用此漏洞可以通过将任意命令作为低权限用户注入特定文件,然后等待管理员用户执行特定命令。以下产品和版本受到影响:18.3 及之前版本、18.4、19.2、20.1、20.3、20.4、20.5
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco SD-WAN vManage | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-20695 | 10.0 CRITICAL | Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability |
| CVE-2022-20622 | 8.6 HIGH | Cisco Embedded Wireless Controller with Catalyst Access Points IP Flood Denial of Service |
| CVE-2022-20678 | 8.6 HIGH | Cisco IOS XE Software AppNav-XE Denial of Service Vulnerability |
| CVE-2022-20714 | 8.6 HIGH | Cisco IOS XR Software for ASR 9000 Series Routers Lightspeed-Plus Line Cards Denial of Ser |
| CVE-2022-20697 | 8.6 HIGH | Cisco IOS and IOS XE Software Web Services Denial of Service Vulnerability |
| CVE-2022-20682 | 8.6 HIGH | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Se |
| CVE-2022-20683 | 8.6 HIGH | Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility |
| CVE-2022-20716 | 7.8 HIGH | Cisco SD-WAN Solution Improper Access Control Vulnerability |
| CVE-2022-20681 | 7.8 HIGH | Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Catalyst 9000 Family Wir |
| CVE-2022-20692 | 7.7 HIGH | Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability |
| CVE-2022-20684 | 7.4 HIGH | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of |
| CVE-2022-20761 | 7.4 HIGH | Cisco 1000 Series Connected Grid Router Integrated Wireless Access Point Denial of Service |
| CVE-2022-20694 | 6.8 MEDIUM | Cisco IOS XE Software Border Gateway Protocol Resource Public Key Infrastructure Denial of |
| CVE-2022-20679 | 6.8 MEDIUM | Cisco IOS XE Software IPSec Denial of Service Vulnerability |
| CVE-2022-20758 | 6.8 MEDIUM | Cisco IOS XR Software Border Gateway Protocol Ethernet VPN Denial of Service Vulnerability |
| CVE-2022-20747 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Information Disclosure Vulnerability |
| CVE-2022-20735 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Request Forgery Vulnerability |
| CVE-2022-20726 | 5.5 MEDIUM | Cisco IOx Application Hosting Environment Vulnerabilities |
| CVE-2022-20677 | 5.5 MEDIUM | Cisco IOx Application Hosting Environment Vulnerabilities |
| CVE-2022-20725 | 5.5 MEDIUM | Cisco IOx Application Hosting Environment Vulnerabilities |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet