CVE-2020-3180: Cisco SD-WAN Solution Software Static Credentials Vulnerability
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-3180.
What is the severity level of CVE-2020-3180?
CVE-2020-3180 has a severity level of 7.8 (high).
What is the affected software?
The affected software includes Cisco SD-WAN Solution Software versions between 18.3.0 and 18.3.6, versions between 18.4.0 and 18.4.5, and versions between 19.2.0 and 19.2.2.
What is the vulnerability description of CVE-2020-3180?
CVE-2020-3180 is a vulnerability in Cisco SD-WAN Solution Software that allows an unauthenticated, local attacker to access an affected device using a default, static password.
Is Cisco 1100-4g Integrated Services Router vulnerable to CVE-2020-3180?
No, Cisco 1100-4g Integrated Services Router is not vulnerable to CVE-2020-3180.