Sd Wan

Vendor:

First CVE: Oct 5, 2018 · Active for 7 years

27
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
3.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sd Wan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2018
7 years ago
Most Recent CVE
Sep 27, 2023
1,031 days ago

CVE Severity & Scoring

Sd Wan27 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local14 (51.9%)
Network12 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.7%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low19 (70.4%)
High2 (7.4%)
None6 (22.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access contro
Sep 30, 20227.873YESNO
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The
Nov 6, 20206.553NONO
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to imp
Oct 5, 20189.831NONO
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to acces
Jul 31, 20209.930NONO
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. Th
Jan 24, 20198.829NONO
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with
Jun 20, 20198.828NONO
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper acc
Sep 30, 20227.826NONO
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control
Apr 15, 20227.825NONO
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is d
Nov 6, 20207.825NONO
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to
Nov 6, 20207.825NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
1 CVE
3.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Sd Wan

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20.9.018.10.3%00
20.916.70.2%00
20.8.018.10.3%00
20.827.36.4%10
20.7.115.30.8%00
20.717.50.6%00
20.617.50.6%00
20.3.515.30.8%00
20.3.4.215.30.8%00
20.3.4.115.30.8%00
20.3.115.40.6%00
18.3.019.81.1%00