CVE-2020-8273
https://notcve.org/view.php?id=CVE-2020-8273
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. Una escalada de privilegios de un usuario autenticado a root en Citrix SD-WAN center, versiones anteriores a 11.2.2, 11.1.2b y 10.2.8 • https://support.citrix.com/article/CTX285061 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2020-8272
https://notcve.org/view.php?id=CVE-2020-8272
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 Una Omisión de Autenticación resultando en una exposición de la funcionalidad SD-WAN en Citrix SD-WAN Center versiones anteriores a 11.2.2, 11.1.2b y 10.2.8 • https://support.citrix.com/article/CTX285061 • CWE-287: Improper Authentication •
CVE-2020-8271
https://notcve.org/view.php?id=CVE-2020-8271
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 Una ejecución de código remota no autenticada con privilegios root en Citrix SD-WAN Center versiones anteriores a 11.2.2, 11.1.2b y 10.2.8 • https://support.citrix.com/article/CTX285061 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •
CVE-2020-3600 – Cisco SD-WAN Software Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-3600
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient security controls on the CLI. An attacker could exploit this vulnerability by using an affected CLI utility that is running on an affected system. A successful exploit could allow the attacker to gain root privileges. Una vulnerabilidad en Cisco SD-WAN Software, podría permitir a un atacante local autenticado elevar privilegios a root en el sistema operativo subyacente. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vepeshlg-tJghOQcA • CWE-269: Improper Privilege Management CWE-863: Incorrect Authorization •
CVE-2020-3595 – Cisco SD-WAN Software Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-3595
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is due to incorrect permissions being set when the affected command is executed. An attacker could exploit this vulnerability by executing the affected command on an affected system. A successful exploit could allow the attacker to gain root privileges. Una vulnerabilidad en Cisco SD-WAN Software podría permitir a un atacante local autenticado elevar privilegios al grupo root en el sistema operativo subyacente. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vepegr-4xynYLUj • CWE-269: Improper Privilege Management CWE-732: Incorrect Permission Assignment for Critical Resource •