Improper Authentication in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2021-1284

 

Improper Authentication in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2021-1284

Published: May 6, 2021


Vulnerability identifier: #VU52919
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1284
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker on the local network can bypass authentication process and modify the configuration of an affected system.

Successful exploitation of the vulnerability may result in full system compromise.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2021-1284

Install updates from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.4.1, 20.5.1

External References

Related Security Bulletins