Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3381

Опубликовано: 16 июл. 2020
Источник: nvd
CVSS3: 8.8
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия до 18.3.0 (включая)
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия от 18.4.0 (включая) до 19.2.3 (исключая)
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия от 19.3.0 (включая) до 20.1 (включая)

Одно из

cpe:2.3:h:cisco:1100-4g_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltegb_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltena_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-6g_integrated_services_router:-:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00641
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость веб-интерфейса управления vManage программно-определяемой сети Cisco SD-WAN, позволяющая нарушителю выполнить чтение и запись произвольных файлов в целевой системе

EPSS

Процентиль: 70%
0.00641
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22
CWE-22