VendorsCiscocatalyst_sd-wan_manager19.2.099
Vulnerabilities

Cisco Catalyst SD-WAN Manager 19.2.099

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2020-26071
Cisco SD-WAN vEdge Arbitrary File Creation Vulnerability
Published 2024-11-18 · Analyzed
8.4EPSS 0.002
CVE-2020-26064
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.
Published 2023-08-04 · Modified
8.1EPSS 0.007
CVE-2020-26074
Cisco SD-WAN vManage Privilege Escalation Vulnerability
Published 2024-11-18 · Analyzed
7.8EPSS 0.002
CVE-2025-20122
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
Published 2025-05-07 · Analyzed
7.8EPSS 0.001
CVE-2020-26073
Cisco SD-WAN vManage Directory Traversal Vulnerability
Published 2024-11-18 · Analyzed
7.5EPSS 0.126
CVE-2021-1462
Cisco SD-WAN vManage Software Privilege Escalation Vulnerability
Published 2024-11-18 · Analyzed
6.7EPSS 0.002
CVE-2020-26065
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.
Published 2023-08-04 · Modified
6.5EPSS 0.017
CVE-2021-1491
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.013
CVE-2025-20187
Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability
Published 2025-05-07 · Analyzed
6.5EPSS 0.013
CVE-2021-1484
Cisco SD-WAN vManage Command Injection Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.012
CVE-2021-1232
Cisco SD-WAN vManage Information Disclosure Vulnerability
Published 2024-11-18 · Analyzed
6.5EPSS 0.011
CVE-2020-26066
Cisco SD-WAN vManage Software XML External Entity Vulnerability
Published 2024-11-18 · Analyzed
6.5EPSS 0.006
CVE-2023-20261
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.
Published 2023-10-18 · Modified
6.5EPSS 0.005
CVE-2021-1483
Cisco SD-WAN vManage Software XML External Entity Vulnerability
Published 2024-11-15 · Analyzed
6.4EPSS 0.009
CVE-2021-1482
Cisco SD-WAN vManage Authorization Bypass Vulnerability
Published 2024-11-15 · Analyzed
6.4EPSS 0.006
CVE-2025-20157
Cisco Catalyst vManage Certificate Validation Vulnerability
Published 2025-05-07 · Analyzed
5.9EPSS 0.003
CVE-2025-20213
Cisco Catalyst SDWAN Manager Arbitrary File Overwrite Vulnerability
Published 2025-05-07 · Analyzed
5.5EPSS 0.002
CVE-2021-1466
Cisco SD-WAN vDaemon Buffer Overflow Vulnerability
Published 2024-11-15 · Analyzed
5.4EPSS 0.006
CVE-2025-20147
Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability
Published 2025-05-07 · Analyzed
5.4EPSS 0.003
CVE-2021-1234
Cisco SD-WAN vManage Information Disclosure Vulnerabilities
Published 2024-11-18 · Analyzed
5.3EPSS 0.008
CVE-2021-1464
Cisco SD-WAN vManage Authorization Bypass Vulnerability
Published 2024-11-15 · Analyzed
5.0EPSS 0.013
CVE-2021-1470
Cisco SD-WAN SQL Injection Vulnerability
Published 2024-11-15 · Analyzed
4.9EPSS 0.011
CVE-2025-20216
Cisco Catalyst SD-WAN Manager Reflected HTML Injection Vulnerability
Published 2025-05-07 · Analyzed
4.7EPSS 0.003
CVE-2021-1465
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to write arbitrary files on the affected system.
Published 2024-11-18 · Analyzed
4.3EPSS 0.012
CVE-2021-1481
Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability
Published 2024-11-15 · Analyzed
4.3EPSS 0.008