Home Latest News Security Vulnerabilities in Cisco SD-WAN vManage Software

Security Vulnerabilities in Cisco SD-WAN vManage Software

by CISOCONNECT Bureau

Several security vulnerabilities in Cisco SD-WAN vManage Software may enable a remote attacker to execute arbitrary code or a local attacker to gain escalated privileges on an affected device.

Cisco has issued upgrades to its software to fix the flaws and there are no workarounds available to fix these flaws.

Cisco explained that these security vulnerabilities are not dependent on one another. The exploitation of one of the vulnerabilities is not required to exploit another vulnerability. As well, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.

If your Cisco system is running a vulnerable version of Cisco SD-WAN vManage Software, you’re vulnerable.

Cisco reported that the Cisco products namely IOS XE SD-WAN Software, SD-WAN cEdge Routers, SD-WAN vBond Orchestrator Software, SD-WAN vEdge Routers, SD-WAN vSmart Controller Software, are not affected by these vulnerabilities

The security vulnerabilities found in the Cisco products are listed below

* CVE-2021-1479: Cisco SD-WAN vManage Remote Management Buffer Overflow Vulnerability- CVSS Base Score: 9.8

* CVE-2021-1137: Cisco SD-WAN vManage Privilege Escalation Vulnerability – CVSS Base Score: 7.8

* CVE-2021-1480: Cisco SD-WAN vManage Privilege Escalation Vulnerability- CVSS Base Score: 7.8

Patched Software
Cisco has published free software updates to fix the vulnerabilities. Customers can only install software versions and feature sets for which they have purchased a licence, and they can expect support for such versions and feature sets.

Cisco advised customers to check the Cisco Security Advisories page on a regular basis to assess their exposure and a full update solution.

Recommended for You

Recommended for You

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Close Read More

See Ads