Cisco SD-WAN Software Multiple Products CLI Command Injection (cisco-sa-cli-cmdinj-4MttWZPB)

high Nessus Plugin ID 164375

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco SD-WAN Software is affected by multiple vulnerabilities.
Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCvm76596, CSCvq21764, CSCvq22323, CSCvq58164, CSCvq58168, CSCvq58183, CSCvq58204, CSCvq58224, CSCvq58226, CSCvz49669

See Also

http://www.nessus.org/u?e56d38ec

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm76596

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq21764

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq22323

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58164

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58168

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58183

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58204

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58224

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq58226

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz49669

Plugin Details

Severity: High

ID: 164375

File Name: cisco-sa-sd-wan-cli-cmdinj-4MttWZPB-iosxe.nasl

Version: 1.5

Type: local

Family: CISCO

Published: 8/24/2022

Updated: 11/18/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.1

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2022-20655

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:sd-wan_vmanage, cpe:/o:cisco:sd-wan_firmware

Required KB Items: Cisco/Viptela/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 1/19/2022

Vulnerability Publication Date: 1/19/2022

Reference Information

CVE: CVE-2022-20655