Lucene search

K
ciscoCiscoCISCO-SA-IOSXE-SDWPATHTRAV-NSRUE2MT
HistoryMar 24, 2021 - 4:00 p.m.

Cisco IOS XE SD-WAN Software Path Traversal Vulnerability

2021-03-2416:00:00
tools.cisco.com
47
cisco
vulnerability
path traversal
cli
software
update
authentication
local attacker
read access
insufficient validation
crafted request
sensitive files
security advisory

EPSS

0

Percentile

9.9%

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-sdwpathtrav-nsrue2Mt [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-sdwpathtrav-nsrue2Mt”]

Affected configurations

Vulners
Node
ciscocisco_ios_xe_softwareMatch16.11
OR
ciscocisco_ios_xe_softwareMatch16.12
OR
ciscocisco_ios_xe_softwareMatch17.1
OR
ciscocisco_ios_xe_softwareMatch17.2
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoios_xe_sd-wanMatchany
OR
ciscocisco_ios_xe_softwareMatch16.11.1
OR
ciscocisco_ios_xe_softwareMatch16.11.1a
OR
ciscocisco_ios_xe_softwareMatch16.11.1b
OR
ciscocisco_ios_xe_softwareMatch16.11.2
OR
ciscocisco_ios_xe_softwareMatch16.11.1s
OR
ciscocisco_ios_xe_softwareMatch16.11.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1
OR
ciscocisco_ios_xe_softwareMatch16.12.1s
OR
ciscocisco_ios_xe_softwareMatch16.12.1a
OR
ciscocisco_ios_xe_softwareMatch16.12.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1w
OR
ciscocisco_ios_xe_softwareMatch16.12.2
OR
ciscocisco_ios_xe_softwareMatch16.12.1y
OR
ciscocisco_ios_xe_softwareMatch16.12.2a
OR
ciscocisco_ios_xe_softwareMatch16.12.3
OR
ciscocisco_ios_xe_softwareMatch16.12.2s
OR
ciscocisco_ios_xe_softwareMatch16.12.1x
OR
ciscocisco_ios_xe_softwareMatch16.12.1t
OR
ciscocisco_ios_xe_softwareMatch16.12.2t
OR
ciscocisco_ios_xe_softwareMatch16.12.4
OR
ciscocisco_ios_xe_softwareMatch16.12.3s
OR
ciscocisco_ios_xe_softwareMatch16.12.1z
OR
ciscocisco_ios_xe_softwareMatch16.12.3a
OR
ciscocisco_ios_xe_softwareMatch16.12.4a
OR
ciscocisco_ios_xe_softwareMatch16.12.1z2
OR
ciscocisco_ios_xe_softwareMatch17.1.1
OR
ciscocisco_ios_xe_softwareMatch17.1.1a
OR
ciscocisco_ios_xe_softwareMatch17.1.1s
OR
ciscocisco_ios_xe_softwareMatch17.1.2
OR
ciscocisco_ios_xe_softwareMatch17.1.1t
OR
ciscocisco_ios_xe_softwareMatch17.2.1
OR
ciscocisco_ios_xe_softwareMatch17.2.1r
OR
ciscocisco_ios_xe_softwareMatch17.2.1a
OR
ciscocisco_ios_xe_softwareMatch17.2.1v
OR
ciscocisco_ios_xe_softwareMatch17.2.2
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoios_xe_sd-wanMatchany
VendorProductVersionCPE
ciscocisco_ios_xe_software16.11cpe:2.3:a:cisco:cisco_ios_xe_software:16.11:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.12cpe:2.3:a:cisco:cisco_ios_xe_software:16.12:*:*:*:*:*:*:*
ciscocisco_ios_xe_software17.1cpe:2.3:a:cisco:cisco_ios_xe_software:17.1:*:*:*:*:*:*:*
ciscocisco_ios_xe_software17.2cpe:2.3:a:cisco:cisco_ios_xe_software:17.2:*:*:*:*:*:*:*
ciscocisco_ios_xe_softwareanycpe:2.3:a:cisco:cisco_ios_xe_software:any:*:*:*:*:*:*:*
ciscoios_xe_sd-wananycpe:2.3:o:cisco:ios_xe_sd-wan:any:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1cpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1acpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1a:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1bcpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1b:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.2cpe:2.3:a:cisco:cisco_ios_xe_software:16.11.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 411

EPSS

0

Percentile

9.9%

Related for CISCO-SA-IOSXE-SDWPATHTRAV-NSRUE2MT