Known vulnerabilities in Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
Vendor:
Cisco Systems, Inc
Software CPE:
cpe:2.3:h:cisco_systems:cisco_sd-wan_vsmart_controller:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
29
Public exploits:
2
Known exploited (KEV):
3
Highest CVSSv4 Score:
10
Breakdown by Severity Chart
Vulnerabilities (29)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131450 - Improper Authentication CVE-2026-20182 |
CWE-287 | Critical | 20.15.4.3, 20.15.5.1, 20.18.2.2, 26.1.1 | 14.05.2026 |
SB20260514104 |
||
| #VU123273 - Improper Authentication CVE-2026-20127 |
CWE-287 | Critical | 20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1 | 25.02.2026 |
SB2026022553 |
||
| #VU67748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-20850 |
CWE-22 | Low | - | 29.09.2022 |
SB2022092928 |
||
| #VU67747 - Improper Access Control CVE-2022-20818 |
CWE-284 | Low | - | 29.09.2022 |
SB2022092927 |
||
| #VU67746 - Improper Access Control CVE-2022-20775 |
CWE-284 | Low | - | 29.09.2022 |
SB2022092926 |
||
| #VU62345 - Improper Access Control CVE-2022-20716 |
CWE-284 | Low | 20.6.1, 20.7.1 | 15.04.2022 |
SB2022041503 |
||
| #VU56871 - Command injection CVE-2021-34726 |
CWE-77 | Low | - | 24.09.2021 |
SB2021092423 |
||
| #VU53756 - Execution with Unnecessary Privileges CVE-2021-1528 |
CWE-250 | Low | 20.4.2, 20.5.1 | 03.06.2021 |
SB2021060305 |
||
| #VU52934 - Improper input validation CVE-2021-1514 |
CWE-20 | Low | 18.3.0, 18.4.0, 19.1.0, 19.2.0, 19.3.0, 20.1.1, 20.3.1, 20.4.1, 20.5.1 | 06.05.2021 |
SB2021050623 |
||
| #VU52932 - Improper input validation CVE-2021-1513 |
CWE-20 | Medium | 20.4.1, 20.5.1 | 06.05.2021 |
SB2021050622 |
||
| #VU52931 - Files or Directories Accessible to External Parties CVE-2021-1512 |
CWE-552 | Low | 18.4.6, 19.2.3, 20.1.2, 20.3.1, 20.4.1, 20.5.1 | 06.05.2021 |
SB2021050619 |
||
| #VU49899 - Memory corruption CVE-2021-1301 |
CWE-119 | Medium | - | 21.01.2021 |
SB2021012109 |
||
| #VU49895 - Command injection CVE-2021-1263 |
CWE-77 | Low | - | 21.01.2021 |
SB2021012108 |
||
| #VU49894 - Command injection CVE-2021-1262 |
CWE-77 | Low | - | 21.01.2021 |
SB2021012108 |
||
| #VU50012 - Memory corruption CVE-2021-1273 |
CWE-119 | Medium | - | 20.01.2021 |
SB2021012618 |
||
| #VU50013 - NULL Pointer Dereference CVE-2021-1274 |
CWE-476 | Medium | - | 20.01.2021 |
SB2021012618 |
||
| #VU50014 - Improper Link Resolution Before File Access ('Link Following') CVE-2021-1278 |
CWE-59 | Low | - | 20.01.2021 |
SB2021012618 |
||
| #VU50015 - Improper input validation CVE-2021-1279 |
CWE-20 | Medium | - | 20.01.2021 |
SB2021012618 |
||
| #VU49892 - Command injection CVE-2021-1260 |
CWE-77 | Low | - | 20.01.2021 |
SB2021012108 |
||
| #VU49898 - Memory corruption CVE-2021-1300 |
CWE-119 | High | - | 20.01.2021 |
SB2021012109 |
Showing elements 1 - 20 out of 29