threat
engine
.sh
Back
·
··:··
Home
/
Product
/
arubanetworks sd wan
Product
arubanetworks sd wan
133 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-44871
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS
7.2
HIGH
CVE-2026-44873
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts ar
5.4
MEDIUM
CVE-2026-44872
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful e
7.2
HIGH
CVE-2026-44870
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS
7.2
HIGH
CVE-2026-44869
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44868
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44867
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44866
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44865
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44864
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2
HIGH
CVE-2026-44863
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2
HIGH
CVE-2026-44862
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2
HIGH
CVE-2026-44861
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2
HIGH
CVE-2026-44860
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2
HIGH
CVE-2026-44859
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2
HIGH
CVE-2026-44858
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2
HIGH
CVE-2026-44857
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2
HIGH
CVE-2026-44856
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2
HIGH
CVE-2026-44855
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2
HIGH
CVE-2026-44854
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44853
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2
HIGH
CVE-2026-44852
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerabilit
7.2
HIGH
CVE-2026-23827
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthen
7.5
HIGH
CVE-2026-23826
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploi
7.5
HIGH
CVE-2026-23825
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could ex
7.5
HIGH
CVE-2026-23824
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could ex
7.5
HIGH
CVE-2023-20034
>= 20.3 and < 20.3.4
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote at
7.5
HIGH
CVE-2023-20113
< 20.6.5
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote atta
6.5
MEDIUM
CVE-2023-22778
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-sit
4.8
MEDIUM
CVE-2023-22777
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitatio
4.9
MEDIUM
CVE-2023-22776
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulner
4.9
MEDIUM
CVE-2023-22775
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interfac
6.5
MEDIUM
CVE-2023-22774
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnera
7.2
HIGH
CVE-2023-22773
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnera
7.2
HIGH
CVE-2023-22772
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of thi
6.5
MEDIUM
CVE-2023-22771
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vul
6.8
MEDIUM
CVE-2023-22770
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22769
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22768
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22767
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22766
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22765
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22764
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22763
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22762
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2023-22761
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2
HIGH
CVE-2023-22760
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2
HIGH
CVE-2023-22759
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2
HIGH
CVE-2023-22758
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2
HIGH
CVE-2023-22757
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1
HIGH
CVE-2023-22756
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1
HIGH
CVE-2023-22755
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1
HIGH
CVE-2023-22754
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1
HIGH
CVE-2023-22753
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1
HIGH
CVE-2023-22752
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending speciall
9.8
CRITICAL
CVE-2023-22751
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending speciall
9.8
CRITICAL
CVE-2023-22750
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8
CRITICAL
CVE-2023-22749
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8
CRITICAL
CVE-2023-22748
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8
CRITICAL
CVE-2023-22747
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8
CRITICAL
CVE-2022-37912
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37911
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful
3.8
LOW
CVE-2022-37910
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result
4.4
MEDIUM
CVE-2022-37909
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSID
5.3
MEDIUM
CVE-2022-37908
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation c
5.8
MEDIUM
CVE-2022-37907
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) conditio
5.8
MEDIUM
CVE-2022-37906
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnera
6.5
MEDIUM
CVE-2022-37905
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the b
6.6
MEDIUM
CVE-2022-37904
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the b
6.6
MEDIUM
CVE-2022-37903
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via t
7.2
HIGH
CVE-2022-37902
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37901
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37900
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37899
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37898
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2
HIGH
CVE-2022-37897
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted p
9.8
CRITICAL
CVE-2022-20930
< 20.6.2
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt
6.7
MEDIUM
CVE-2022-20850
< 18.4.5
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, loc
5.5
MEDIUM
CVE-2022-20844
>= 20.4.1 and < 20.6.3
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage
5.3
MEDIUM
CVE-2022-20818
< 20.9
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privile
7.8
HIGH
CVE-2022-20775
< 20.6.3
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. T
7.8
HIGH
CVE-2022-20716
>= 18.4 and < 20.6.1
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. Thi
7.8
HIGH
CVE-2021-22956
< 10.2.9c
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow a
7.5
HIGH
CVE-2021-34726
< 18.4.6
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to b
6.7
MEDIUM
CVE-2021-1612
< 17.3.4
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files
5.5
MEDIUM
CVE-2021-1589
>= 20.3 and < 20.3.4
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to
6.5
MEDIUM
CVE-2021-37733
>= 2.2.0.0 and < 2.2.0.4
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio
4.9
MEDIUM
CVE-2021-37731
>= 2.2.0.0 and < 2.2.0.4
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version
6.2
MEDIUM
CVE-2021-37729
>= 2.2.0.0 and < 2.2.0.4
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio
6.5
MEDIUM
CVE-2021-37725
>= 2.2.0.0 and < 2.2.0.4
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating Sys
8.1
HIGH
CVE-2021-37722
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37721
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37720
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37719
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37718
>= 2.2.0.0 and < 2.2.0.6
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37717
>= 2.2.0.0 and < 2.2.0.6
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2
HIGH
CVE-2021-37716
>= 2.2.0.0 and < 2.2.0.4
A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versi
9.8
CRITICAL
CVE-2021-1614
>= 18.4.0 and < 18.4.6
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unaut
5.3
MEDIUM
CVE-2020-24637
< 2.1.0.2
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this v
7.2
HIGH
CVE-2020-24634
< 2.1.0.2
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networ
9.8
CRITICAL
CVE-2020-24633
< 2.1.0.2
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially
9.8
CRITICAL
CVE-2020-8273
>= 10.2.0 and < 10.2.8
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
8.8
HIGH
CVE-2020-8272
>= 10.2.0 and < 10.2.8
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10
7.5
HIGH
CVE-2020-8271
>= 10.2.0 and < 10.2.8
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
9.8
CRITICAL
CVE-2020-3600
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8
HIGH
CVE-2020-3595
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the u
7.8
HIGH
CVE-2020-3594
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8
HIGH
CVE-2020-3593
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8
HIGH
CVE-2020-27128
< 20.3.1
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker t
6.5
MEDIUM
CVE-2020-3536
<= 20.1.2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attack
5.4
MEDIUM
CVE-2020-3375
<= 18.3.0
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an
9.8
CRITICAL
CVE-2020-3374
<= 18.3.0
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attack
9.9
CRITICAL
CVE-2020-3180
>= 18.3.0 and < 18.3.6
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by u
7.8
HIGH
CVE-2019-12992
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
8.8
HIGH
CVE-2019-12991
>= 10.2.0 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
8.8
HIGH
CVE-2019-12990
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
9.8
CRITICAL
CVE-2019-12989
>= 10.2.0 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
9.8
CRITICAL
CVE-2019-12988
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
9.8
CRITICAL
CVE-2019-12987
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
9.8
CRITICAL
CVE-2019-12986
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).
9.8
CRITICAL
CVE-2019-12985
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
9.8
CRITICAL
CVE-2019-1624
< 18.4.0
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to
8.8
HIGH
CVE-2019-11550
>= 10.1.0 and <= 10.1.2
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
5.9
MEDIUM
CVE-2019-1650
< 18.4.0
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the und
8.8
HIGH
CVE-2019-1648
< 18.4.0
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain
7.8
HIGH
CVE-2019-1647
< 18.4.0
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have dir
8.0
HIGH
CVE-2019-1646
< 18.4.0
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges
7.8
HIGH
CVE-2018-17448
all versions
An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before
9.8
CRITICAL
CVE-2018-17447
all versions
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and
7.5
HIGH
CVE-2018-17446
all versions
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
9.8
CRITICAL
CVE-2018-17445
all versions
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
9.8
CRITICAL
CVE-2018-17444
all versions
A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.
7.5
HIGH
CVE-2018-15387
>= 17.2.0 and < 17.2.8
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on a
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin