PT-2021-1861 · Cisco · Cisco Sd-Wan Vedge Routers+7

Arthur Vidineyev

·

Published

2021-01-20

·

Updated

2023-10-06

·

CVE-2021-1274

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN products (affected versions not specified) Cisco IOS XE SD-WAN (affected versions not specified) Cisco SD-WAN vBond Orchestrator (affected versions not specified) Cisco SD-WAN vEdge Cloud Routers (affected versions not specified) Cisco SD-WAN vEdge Routers (affected versions not specified) Cisco SD-WAN vSmart Controller (affected versions not specified) Cisco SD-WAN vManage (affected versions not specified)
Description Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. The vulnerability is related to a buffer overflow in the UDP protocol implementation.
Recommendations For Cisco SD-WAN products, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco IOS XE SD-WAN, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco SD-WAN vBond Orchestrator, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco SD-WAN vEdge Cloud Routers, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco SD-WAN vEdge Routers, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco SD-WAN vSmart Controller, update to a version that includes the software updates released by Cisco to address these vulnerabilities. For Cisco SD-WAN vManage, update to a version that includes the software updates released by Cisco to address these vulnerabilities.

Fix

DoS

Buffer Overflow

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00628
CVE-2021-1274

Affected Products

Cisco Ios Xe Sd-Wan
Cisco Ios Xe
Cisco Sd-Wan
Cisco Sd-Wan Vbond Orchestrator
Cisco Sd-Wan Vedge Cloud Routers
Cisco Sd-Wan Vedge Routers
Cisco Sd-Wan Vmanage
Cisco Sd-Wan Vsmart Controller