Improper Authentication in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2021-1284
Published: May 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker on the local network can bypass authentication process and modify the configuration of an affected system.
Successful exploitation of the vulnerability may result in full system compromise.
Affected software
How to mitigate CVE-2021-1284
External References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-auth-bypass-65aYqcS2
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu28360
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu28390
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu28402
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu28454
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv67264