XML External Entity Processing Issue in Cisco SD-WAN vManage Software
CVE-2020-26064
6.5MEDIUM
What is CVE-2020-26064?
A vulnerability exists in the web UI of Cisco SD-WAN vManage Software that may enable an authenticated attacker to gain unauthorized read and write access to sensitive data stored on the affected system. This arises from improper handling of XML External Entity (XXE) entries during the parsing of specific XML files. The exploitation involves convincing a user to import a maliciously crafted XML file, leading to unauthorized data manipulation within the application.
Affected Version(s)
Cisco SD-WAN vManage 17.2.6
Cisco SD-WAN vManage 17.2.7
Cisco SD-WAN vManage 17.2.8