Rewterz Threat Alert – Lazarus APT Latest Tactics and IOCs
April 21, 2021Rewterz Threat Advisory – Multiple Oracle MySQL Vulnerabilities
April 22, 2021Rewterz Threat Alert – Lazarus APT Latest Tactics and IOCs
April 21, 2021Rewterz Threat Advisory – Multiple Oracle MySQL Vulnerabilities
April 22, 2021Severity
Medium
Analysis Summary
CVE-2021-1491
Cisco SD-WAN vManage Software allows a remote authenticated attacker to obtain sensitive information. This is caused by improper file scope limiting. An attacker can exploit this vulnerability by creating a specific file reference on the file system and then accessing it through the web-based management interface. This vulnerability can be exploited to read arbitrary files from the file system of the underlying operating system, and the information can be used to launch further attacks against the affected system.
CVE-2021-1484
Cisco SD-WAN vManage Software allows a remote authenticated attacker to cause a denial of service condition. This is caused by improper input validation of user-supplied input to the device template configuration. This vulnerability can be exploited by a remote authenticated attacker to cause denial-of-service conditions.
CVE-2021-1483
Cisco SD-WAN vManage Software allows a remote authenticated attacker to bypass security restrictions. This is caused by improper handling of XML External Entity (XXE) entries. An attacker can exploit this vulnerability by using specially crafted XML content to read and write files on the system.
CVE-2021-1482
Cisco SD-WAN vManage Software allows a remote authenticated attacker to bypass security restrictions. This is caused by improper authorization validation. An attacker can exploit this vulnerability by using specially crafted HTTP requests to the web-based management interface to bypass access restrictions and obtain sensitive information.
CVE-2021-1481
Cisco SD-WAN vManage Software allows a remote authenticated attacker to obtain sensitive information. This is caused by improper input validation by the web-based management interface. An attacker can exploit this vulnerability by using specially crafted HTTP to obtain sensitive information and use this information to launch further attacks against the affected system.
Impact
- Denial-of-Service
- Security Bypass
- Information Disclosure
Affected Vendors
Cisco
Affected Products
Cisco SD-WAN vManage Software 20.5.0 and prior versions
Remediation
Download the latest patches and upgrade to the latest software to mitigate the risks. Visit the website for more information at https://tools.cisco.com/security/center/publicationListing.x