Improper Authorization in Cisco SD-WAN vManage Software



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-3374
CWE-ID CWE-285
Exploitation vector Network
Public exploit N/A
Vulnerable software
Cisco SD-WAN vManage
Other software / Other software solutions

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Improper Authorization

EUVDB-ID: #VU32920

Risk: Medium

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-3374

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to insufficient authorization checking on the affected system. A remote authenticated attacker can send specially crafted HTTP requests and gain privileges beyond what would normally be authorized for their configured user authorization level.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Cisco SD-WAN vManage: 18.3 - 20.1

CPE2.3 External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uabvman-SYGzt8Bv


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###