Known vulnerabilities in Cisco SD-WAN

Software: Cisco SD-WAN
Software CPE: cpe:2.3:a:cisco_systems:cisco_sd-wan:*:*:*:*:*:*:*:*
Total vulnerabilities: 66
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco SD-WAN Cisco SD-WAN is affected by 66 known vulnerabilities: 1 critical, 4 high, 18 medium, 43 low Critical High Medium Low

Vulnerabilities (66)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-20850
CWE-22 Low
No
No
18.4.5 29.09.2022 SB2022092928
#VU67747 - Improper Access Control
CVE-2022-20818
CWE-284 Low
No
No
- 29.09.2022 SB2022092927
#VU67746 - Improper Access Control
CVE-2022-20775
CWE-284 Low
No
Exploited
20.6.4, 20.7.2, 20.8.1 29.09.2022 SB2022092926
#VU67730 - Argument Injection or Modification
CVE-2022-20930
CWE-88 Low
No
No
20.6.2, 20.8.1, 20.9.1 29.09.2022 SB2022092905
#VU56871 - Command injection
CVE-2021-34726
CWE-77 Low
No
No
18.4.6, 19.2.3, 20.1.1.2, 20.1.2, 20.3.1, 20.4.1, 20.5.1 24.09.2021 SB2021092423
#VU56867 - Exposure of sensitive information to an unauthorized actor
CVE-2021-1546
CWE-200 Low
No
No
20.4.2, 20.5.2, 20.6.1 24.09.2021 SB2021092419
#VU55240 - Out-of-bounds read
CVE-2021-1614
CWE-125 Medium
No
No
18.4.6, 19.2.3, 20.3.2, 20.4.1, 20.5.1 22.07.2021 SB2021072235
#VU51719 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-1382
CWE-78 Low
No
No
- 25.03.2021 SB2021032510
#VU51706 - Memory corruption
CVE-2021-1433
CWE-119 Critical
No
No
- 24.03.2021 SB2021032415
#VU51705 - Files or Directories Accessible to External Parties
CVE-2021-1434
CWE-552 Low
No
No
- 24.03.2021 SB2021032414
#VU49899 - Memory corruption
CVE-2021-1301
CWE-119 Medium
No
No
18.4.5, 19.2.2, 20.1.1, 20.3.1, 20.3.2, 20.4.1 21.01.2021 SB2021012109
#VU49894 - Command injection
CVE-2021-1262
CWE-77 Low
No
No
20.1.2, 20.3.2, 20.4.1 21.01.2021 SB2021012108
#VU49893 - Command injection
CVE-2021-1261
CWE-77 Low
No
No
20.1.2, 20.3.2, 20.4.1 21.01.2021 SB2021012108
#VU50010 - Improper input validation
CVE-2021-1233
CWE-20 Low
No
No
18.4.3 20.01.2021 SB2021012617
#VU50011 - Memory corruption
CVE-2021-1241
CWE-119 Medium
No
No
18.4.6, 20.1.2, 20.3.1, 20.3.2, 20.4.1 20.01.2021 SB2021012618
#VU50012 - Memory corruption
CVE-2021-1273
CWE-119 Medium
No
No
18.4.6, 20.1.2, 20.3.1, 20.3.2, 20.4.1 20.01.2021 SB2021012618
#VU50014 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-1278
CWE-59 Low
No
No
18.4.6, 20.1.2, 20.3.1, 20.3.2, 20.4.1 20.01.2021 SB2021012618
#VU50015 - Improper input validation
CVE-2021-1279
CWE-20 Medium
No
No
18.4.6, 20.1.2, 20.3.1, 20.3.2, 20.4.1 20.01.2021 SB2021012618
#VU49892 - Command injection
CVE-2021-1260
CWE-77 Low
No
No
20.1.2, 20.3.2, 20.4.1 20.01.2021 SB2021012108
#VU49898 - Memory corruption
CVE-2021-1300
CWE-119 High
No
No
18.4.5, 19.2.2, 20.1.1, 20.3.1, 20.3.2, 20.4.1 20.01.2021 SB2021012109


Showing elements 1 - 20 out of 66