First published: Wed Jan 20 2021(Updated: )
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE sd-wan | ||
Cisco SD-WAN firmware | =18.3.8 | |
Cisco SD-WAN firmware | =18.4.4 | |
Cisco SD-WAN firmware | =19.2.1 | |
Cisco SD-WAN firmware | =19.2.99 | |
Cisco vSmart Controller Firmware | ||
Cisco vEdge 100m router | ||
Cisco vEdge-1000 Firmware | ||
Cisco vEdge 100b | ||
Cisco vEdge 100m router | ||
Cisco vEdge 100wm router | ||
Cisco vEdge 2000 | ||
Cisco vEdge 5000 | ||
Cisco vEdge Cloud | ||
Cisco Catalyst SD-WAN Manager | ||
Cisco vBond Orchestrator |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1300 is a vulnerability in Cisco SD-WAN products that allows an unauthenticated remote attacker to execute attacks against an affected device.
CVE-2021-1300 has a severity rating of 9.8, which is considered critical.
Cisco IOS XE SD-WAN, Cisco SD-WAN Firmware 18.3.8, 18.4.4, 19.2.1, 19.2.99, Cisco SD-WAN Vsmart Controller Firmware are affected by CVE-2021-1300.
To fix CVE-2021-1300, Cisco recommends updating to the latest available software version.
You can find more information about CVE-2021-1300 on the Cisco Security Advisory page.