XML External Entity Processing Issue in Cisco SD-WAN vManage Software
CVE-2020-26064
What is CVE-2020-26064?
A vulnerability exists in the web UI of Cisco SD-WAN vManage Software that may enable an authenticated attacker to gain unauthorized read and write access to sensitive data stored on the affected system. This arises from improper handling of XML External Entity (XXE) entries during the parsing of specific XML files. The exploitation involves convincing a user to import a maliciously crafted XML file, leading to unauthorized data manipulation within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco SD-WAN vManage 17.2.6
Cisco SD-WAN vManage 17.2.7
Cisco SD-WAN vManage 17.2.8
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved