cisco sd-wan-firmware CVE-2020-3405 is a vulnerability in Cisco Sd Wan Firmware
Published on July 16, 2020

Cisco SD-WAN vManage Software XML External Entity Vulnerability
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.

Vendor Advisory NVD

Weakness Type

What is a XXE Vulnerability?

The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

CVE-2020-3405 has been classified to as a XXE vulnerability or weakness.


Products Associated with CVE-2020-3405

Want to know whenever a new CVE is published for Cisco Sd Wan Firmware? stack.watch will email you.

 

Affected Versions

Cisco SD-WAN vManage Version n/a is affected by CVE-2020-3405

Exploit Probability

EPSS
0.31%
Percentile
54.15%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.