Sd Wan Firmware

Vendor:

First CVE: Jun 20, 2019 · Active for 7 years

41
Total CVEs
More Total CVEs than 98% of tracked products
13.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sd Wan Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2019
7 years ago
Most Recent CVE
Jan 20, 2021
2,015 days ago

CVE Severity & Scoring

Sd Wan Firmware41 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local12 (29.3%)
Network28 (68.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.4%)
Attack Complexity
Low41 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None37 (90.2%)
Unknown0 (0.0%)
Required4 (9.8%)
Privileges Required
Low26 (63.4%)
High3 (7.3%)
None12 (29.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vu
Mar 19, 20208.156NONO
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due
Jul 16, 20208.834NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vu
Jan 20, 20219.831NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vu
Jan 20, 20219.830NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attac
Jan 20, 20218.828NONO
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper
Jul 16, 20208.628NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attac
Jan 20, 20218.827NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more in
Jan 20, 20218.627NONO
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage d
Jun 20, 20198.827NONO
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more in
Jan 20, 20218.626NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Sd Wan Firmware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20.4.014.31.3%00
20.417.81.4%00
20.3.017.10.7%00
20.1.0128.11.5%00
19.2.99128.41.8%00
19.2.358.21.8%00
19.2.258.21.5%00
19.2.188.51.7%00
19.2.09817.51.4%00
19.2.09717.51.4%00
19.2.068.11.5%00
19.1.018.80.3%00
18.4.658.21.8%00
18.4.558.21.5%00
18.4.478.61.7%00
18.4.168.31.3%00
18.4.017.80.4%00
18.3.8128.41.8%00
18.3.558.21.5%00
18.3.058.21.8%00