#VU52481 Link following in Cisco SD-WAN vManage - CVE-2021-1491
Published: April 22, 2021
Cisco SD-WAN vManage
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to sensitive information on the system.
The vulnerability exists due to insufficient file scope limiting. A remote authenticated attacker can create a specific file reference on the file system, access it through the web-based management interface and read arbitrary files from the file system of the underlying operating system.