A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to information that they are not authorized to access and make changes to the system that they are not authorized to make.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1100-4g Integrated Services Router
Subscribe
1100-4gltegb Integrated Services Router
Subscribe
1100-4gltena Integrated Services Router
Subscribe
1100-6g Integrated Services Router
Subscribe
Sd-wan Firmware
Subscribe
Vedge 100
Subscribe
Vedge 1000
Subscribe
Vedge 100b
Subscribe
Vedge 100m
Subscribe
Vedge 100wm
Subscribe
Vedge 2000
Subscribe
Vedge 5000
Subscribe
Vedge Cloud Router
Subscribe
Vmanage Network Management System
Subscribe
Vsmart Controller
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24535 | A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to information that they are not authorized to access and make changes to the system that they are not authorized to make. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-15T17:33:22.406Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3264
Updated: 2024-08-04T07:30:57.587Z
Status : Modified
Published: 2020-03-19T16:15:15.487
Modified: 2024-11-21T05:30:41.157
Link: CVE-2020-3264
No data.
OpenCVE Enrichment
No data.
EUVD