CVE-2020-3264: Cisco SD-WAN Solution Buffer Overflow Vulnerability
A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to information that they are not authorized to access and make changes to the system that they are not authorized to make.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco SD-WAN Solution software vulnerability?
The vulnerability ID for this Cisco SD-WAN Solution software vulnerability is CVE-2020-3264.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending crafted traffic to an affected device.
What is the severity rating of CVE-2020-3264?
The severity rating of CVE-2020-3264 is 7.1, which is considered high.
Which versions of Cisco SD-WAN Solution software are affected by this vulnerability?
The versions affected by this vulnerability are 18.4.5, 19.2.0 to 19.2.2, 20.1.0, and 20.3.0.
Are the Cisco Vedge Cloud Router, Cisco Vmanage Network Management System, and Cisco Vsmart Controller vulnerable to this vulnerability?
No, the Cisco Vedge Cloud Router, Cisco Vmanage Network Management System, and Cisco Vsmart Controller are not vulnerable to this vulnerability.