Sd Wan
Vendor:
First CVE: Oct 5, 2018 · Active for 7 years
27
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
3.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sd Wan over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2018
7 years ago
Most Recent CVE
Sep 27, 2023
1,031 days ago
CVE Severity & Scoring
Sd Wan27 CVEs
26%
63%
11%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (51.9%)
Network12 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.7%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low19 (70.4%)
High2 (7.4%)
None6 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-20775HIGH A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
This vulnerability is due to improper access contro | Sep 30, 2022 | 7.8 | 73 | YES | NO |
CVE-2020-27128MEDIUM A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The | Nov 6, 2020 | 6.5 | 53 | NO | NO |
CVE-2018-15387CRITICAL A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to imp | Oct 5, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-3374CRITICAL A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to acces | Jul 31, 2020 | 9.9 | 30 | NO | NO |
CVE-2019-1650HIGH A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. Th | Jan 24, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-1624HIGH A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with | Jun 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-20818HIGH Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper acc | Sep 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-20716HIGH A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control | Apr 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-3595HIGH A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is d | Nov 6, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-3594HIGH A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to | Nov 6, 2020 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
1 CVE
3.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Sd Wan
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 20.9.0 | 1 | 8.1 | 0.3% | 0 | 0 |
| 20.9 | 1 | 6.7 | 0.2% | 0 | 0 |
| 20.8.0 | 1 | 8.1 | 0.3% | 0 | 0 |
| 20.8 | 2 | 7.3 | 6.4% | 1 | 0 |
| 20.7.1 | 1 | 5.3 | 0.8% | 0 | 0 |
| 20.7 | 1 | 7.5 | 0.6% | 0 | 0 |
| 20.6 | 1 | 7.5 | 0.6% | 0 | 0 |
| 20.3.5 | 1 | 5.3 | 0.8% | 0 | 0 |
| 20.3.4.2 | 1 | 5.3 | 0.8% | 0 | 0 |
| 20.3.4.1 | 1 | 5.3 | 0.8% | 0 | 0 |
| 20.3.1 | 1 | 5.4 | 0.6% | 0 | 0 |
| 18.3.0 | 1 | 9.8 | 1.1% | 0 | 0 |