Vulnslist

find the latest Cisco vulnerabilities

Cisco SD-WAN Software Arbitrary File Corruption Vulnerability

cisco-sa-sdwan-arbfile-7Qhd9mCn · Medium · Published · Updated

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-supplied input parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content in any arbitrary files that reside on the underlying host file system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfile-7Qhd9mCn

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2021-1512
Cisco Bug IDsCSCvs98457
CVSS ScoreBase 4.4
Base 4.4 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vEdge Router, Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vContainer

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Catalyst SD-WAN known_affected cisco_csaf CVE-2021-1512 1
Cisco Catalyst SD-WAN Manager known_affected cisco_csaf CVE-2021-1512 1
Cisco SD-WAN vContainer known_affected cisco_csaf CVE-2021-1512 1
Cisco SD-WAN vEdge Cloud known_affected cisco_csaf CVE-2021-1512 1
Cisco SD-WAN vEdge Router known_affected cisco_csaf CVE-2021-1512 1

Related Products

Product CVE Evidence
Cisco Catalyst SD-WAN CVE-2021-1512 Cisco OpenVuln
Cisco Catalyst SD-WAN Manager CVE-2021-1512 Cisco OpenVuln
Cisco SD-WAN vContainer CVE-2021-1512 Cisco OpenVuln
Cisco SD-WAN vEdge Cloud CVE-2021-1512 Cisco OpenVuln
Cisco SD-WAN vEdge Router CVE-2021-1512 Cisco OpenVuln
Cisco SD-WAN CVE-2021-1512 Cisco OpenVuln
Cisco vEdge Routers CVE-2021-1512 Cisco OpenVuln
Cisco Catalyst SD-WAN Software CVE-2021-1512 Cisco OpenVuln