Home/Product/arubanetworks sd wan
Product

arubanetworks sd wan

133 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44871
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS
7.2HIGH
CVE-2026-44873
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts ar
5.4MEDIUM
CVE-2026-44872
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful e
7.2HIGH
CVE-2026-44870
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS
7.2HIGH
CVE-2026-44869
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44868
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44867
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44866
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44865
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44864
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2HIGH
CVE-2026-44863
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2HIGH
CVE-2026-44862
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2HIGH
CVE-2026-44861
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2HIGH
CVE-2026-44860
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line
7.2HIGH
CVE-2026-44859
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2HIGH
CVE-2026-44858
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2HIGH
CVE-2026-44857
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2HIGH
CVE-2026-44856
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2HIGH
CVE-2026-44855
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command
7.2HIGH
CVE-2026-44854
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44853
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful ex
7.2HIGH
CVE-2026-44852
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerabilit
7.2HIGH
CVE-2026-23827
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthen
7.5HIGH
CVE-2026-23826
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploi
7.5HIGH
CVE-2026-23825
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could ex
7.5HIGH
CVE-2026-23824
>= 8.6.0.4-2.2.0.0 and <= 8.6.0.4-2.2.0.7
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could ex
7.5HIGH
CVE-2023-20034
>= 20.3 and < 20.3.4
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote at
7.5HIGH
CVE-2023-20113
< 20.6.5
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote atta
6.5MEDIUM
CVE-2023-22778
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-sit
4.8MEDIUM
CVE-2023-22777
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitatio
4.9MEDIUM
CVE-2023-22776
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulner
4.9MEDIUM
CVE-2023-22775
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interfac
6.5MEDIUM
CVE-2023-22774
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnera
7.2HIGH
CVE-2023-22773
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnera
7.2HIGH
CVE-2023-22772
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of thi
6.5MEDIUM
CVE-2023-22771
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vul
6.8MEDIUM
CVE-2023-22770
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22769
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22768
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22767
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22766
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22765
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22764
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22763
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22762
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2023-22761
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2HIGH
CVE-2023-22760
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2HIGH
CVE-2023-22759
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2HIGH
CVE-2023-22758
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitatio
7.2HIGH
CVE-2023-22757
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1HIGH
CVE-2023-22756
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1HIGH
CVE-2023-22755
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1HIGH
CVE-2023-22754
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1HIGH
CVE-2023-22753
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated rem
8.1HIGH
CVE-2023-22752
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending speciall
9.8CRITICAL
CVE-2023-22751
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending speciall
9.8CRITICAL
CVE-2023-22750
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8CRITICAL
CVE-2023-22749
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8CRITICAL
CVE-2023-22748
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8CRITICAL
CVE-2023-22747
>= 8.7.0.0-2.3.0.0 and <= 8.7.0.0-2.3.0.8
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially
9.8CRITICAL
CVE-2022-37912
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37911
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful
3.8LOW
CVE-2022-37910
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result
4.4MEDIUM
CVE-2022-37909
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSID
5.3MEDIUM
CVE-2022-37908
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation c
5.8MEDIUM
CVE-2022-37907
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) conditio
5.8MEDIUM
CVE-2022-37906
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnera
6.5MEDIUM
CVE-2022-37905
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the b
6.6MEDIUM
CVE-2022-37904
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the b
6.6MEDIUM
CVE-2022-37903
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via t
7.2HIGH
CVE-2022-37902
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37901
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37900
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37899
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37898
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.7
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vuln
7.2HIGH
CVE-2022-37897
>= 8.7.0.0-2.3.0.0 and < 8.7.0.0-2.3.0.6
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted p
9.8CRITICAL
CVE-2022-20930
< 20.6.2
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt
6.7MEDIUM
CVE-2022-20850
< 18.4.5
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, loc
5.5MEDIUM
CVE-2022-20844
>= 20.4.1 and < 20.6.3
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage
5.3MEDIUM
CVE-2022-20818
< 20.9
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privile
7.8HIGH
CVE-2022-20775
< 20.6.3
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. T
7.8HIGH
CVE-2022-20716
>= 18.4 and < 20.6.1
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. Thi
7.8HIGH
CVE-2021-22956
< 10.2.9c
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow a
7.5HIGH
CVE-2021-34726
< 18.4.6
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to b
6.7MEDIUM
CVE-2021-1612
< 17.3.4
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files
5.5MEDIUM
CVE-2021-1589
>= 20.3 and < 20.3.4
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to
6.5MEDIUM
CVE-2021-37733
>= 2.2.0.0 and < 2.2.0.4
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio
4.9MEDIUM
CVE-2021-37731
>= 2.2.0.0 and < 2.2.0.4
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version
6.2MEDIUM
CVE-2021-37729
>= 2.2.0.0 and < 2.2.0.4
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versio
6.5MEDIUM
CVE-2021-37725
>= 2.2.0.0 and < 2.2.0.4
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating Sys
8.1HIGH
CVE-2021-37722
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37721
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37720
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37719
>= 2.2.0.0 and < 2.2.0.4
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37718
>= 2.2.0.0 and < 2.2.0.6
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37717
>= 2.2.0.0 and < 2.2.0.6
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System So
7.2HIGH
CVE-2021-37716
>= 2.2.0.0 and < 2.2.0.4
A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software versi
9.8CRITICAL
CVE-2021-1614
>= 18.4.0 and < 18.4.6
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unaut
5.3MEDIUM
CVE-2020-24637
< 2.1.0.2
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this v
7.2HIGH
CVE-2020-24634
< 2.1.0.2
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networ
9.8CRITICAL
CVE-2020-24633
< 2.1.0.2
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially
9.8CRITICAL
CVE-2020-8273
>= 10.2.0 and < 10.2.8
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
8.8HIGH
CVE-2020-8272
>= 10.2.0 and < 10.2.8
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10
7.5HIGH
CVE-2020-8271
>= 10.2.0 and < 10.2.8
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
9.8CRITICAL
CVE-2020-3600
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8HIGH
CVE-2020-3595
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the u
7.8HIGH
CVE-2020-3594
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8HIGH
CVE-2020-3593
< 20.1.2
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underly
7.8HIGH
CVE-2020-27128
< 20.3.1
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker t
6.5MEDIUM
CVE-2020-3536
<= 20.1.2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attack
5.4MEDIUM
CVE-2020-3375
<= 18.3.0
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an
9.8CRITICAL
CVE-2020-3374
<= 18.3.0
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attack
9.9CRITICAL
CVE-2020-3180
>= 18.3.0 and < 18.3.6
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by u
7.8HIGH
CVE-2019-12992
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
8.8HIGH
CVE-2019-12991
>= 10.2.0 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
8.8HIGH
CVE-2019-12990
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
9.8CRITICAL
CVE-2019-12989
>= 10.2.0 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
9.8CRITICAL
CVE-2019-12988
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
9.8CRITICAL
CVE-2019-12987
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
9.8CRITICAL
CVE-2019-12986
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).
9.8CRITICAL
CVE-2019-12985
>= 10.2 and < 10.2.3
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
9.8CRITICAL
CVE-2019-1624
< 18.4.0
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to
8.8HIGH
CVE-2019-11550
>= 10.1.0 and <= 10.1.2
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
5.9MEDIUM
CVE-2019-1650
< 18.4.0
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the und
8.8HIGH
CVE-2019-1648
< 18.4.0
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain
7.8HIGH
CVE-2019-1647
< 18.4.0
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have dir
8.0HIGH
CVE-2019-1646
< 18.4.0
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges
7.8HIGH
CVE-2018-17448
all versions
An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before
9.8CRITICAL
CVE-2018-17447
all versions
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and
7.5HIGH
CVE-2018-17446
all versions
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
9.8CRITICAL
CVE-2018-17445
all versions
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
9.8CRITICAL
CVE-2018-17444
all versions
A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.
7.5HIGH
CVE-2018-15387
>= 17.2.0 and < 17.2.8
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on a
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin