PT-2021-1897 · Cisco · Cisco Sd-Wan

James Spadaro

·

Published

2021-01-20

·

Updated

2023-10-06

·

CVE-2021-1301

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN products (affected versions not specified)
Description The issue is related to multiple vulnerabilities in Cisco SD-WAN products that could allow an unauthenticated, remote attacker to execute attacks against an affected device. One of the vulnerabilities is associated with the implementation of the NETCONF protocol and is due to insufficient input validation, which could allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-00668
CVE-2021-1301

Affected Products

Cisco Sd-Wan