CVE-2020-26071: Cisco SD-WAN vEdge Arbitrary File Creation Vulnerability
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation for specific commands. An attacker could exploit this vulnerability by including crafted arguments to those specific commands. A successful exploit could allow the attacker to create or overwrite arbitrary files on the affected device, which could result in a DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26071?
CVE-2020-26071 is rated as a high severity vulnerability due to its potential to cause denial of service conditions.
How do I fix CVE-2020-26071?
To mitigate CVE-2020-26071, users should apply the latest patches provided by Cisco for the SD-WAN software.
What kind of attack does CVE-2020-26071 allow?
CVE-2020-26071 allows authenticated, local attackers to create or overwrite arbitrary files on affected devices.
What is the impact of CVE-2020-26071?
The impact of CVE-2020-26071 includes the potential for causing a denial of service on the affected Cisco SD-WAN device.
Which software versions are affected by CVE-2020-26071?
CVE-2020-26071 affects Cisco SD-WAN Software without specifying exact versions, so all users should check for updates.