VendorsCiscoumbrella_virtual_applianceany version
Vulnerabilities

Cisco Umbrella Virtual Appliance any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-12350
A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an affected virtual appliance. An attacker could exploit this vulnerability by using the hypervisor console to connect locally to an affected system and then using the static credentials to log in to an affected virtual appliance. A successful exploit could allow the attacker to log in to the affected appliance with root privileges. Cisco Bug IDs: CSCvg31220.
Published 2017-11-16 · Modified
8.2EPSS 0.004
CVE-2022-20773
Cisco Umbrella Virtual Appliance Static SSH Host Key Vulnerability
Published 2022-04-21 · Analyzed
7.5EPSS 0.012
CVE-2017-6679
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily leveraged for remote support and allowed for authorized/authenticated personnel from the Cisco Umbrella team to access the appliance remotely and obtain full control without explicit customer approval. To address this vulnerability, the Umbrella Virtual Appliance version 2.1.0 now requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established.
Published 2017-12-01 · Analyzed
6.4EPSS 0.003
CVE-2026-20246
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
Published 2026-06-17 · Analyzed
6.0EPSS 0.001