CVE-2021-1301: Cisco SD-WAN Buffer Overflow Vulnerabilities
Published Jan 20, 2021
·Updated
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
16 affected components
cisco IOS XE SD-WAN
cisco Sd-wan Firmware=18.3.8
cisco Sd-wan Firmware=18.4.4
cisco Sd-wan Firmware=19.2.1
cisco Sd-wan Firmware=19.2.99
cisco Sd-wan Vsmart Controller Firmware
cisco Vedge 100 Router
cisco Vedge 1000 Router
cisco Vedge 100b Router
cisco Vedge 100m Router
cisco Vedge 100wm Router
cisco Vedge 2000 Router
cisco Vedge 5000 Router
cisco Vedge Cloud Router
cisco Catalyst SD-WAN Manager
cisco Sd-wan Vbond Orchestrator
Event History
Jan 20, 2021
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-1301?
CVE-2021-1301 refers to multiple vulnerabilities in Cisco SD-WAN products.
2
How severe is CVE-2021-1301?
CVE-2021-1301 has a severity rating of 9.8 (Critical).
3
Which Cisco SD-WAN products are affected by CVE-2021-1301?
Cisco Ios Xe Sd-wan, Cisco Sd-wan Firmware (versions 18.3.8, 18.4.4, 19.2.1, 19.2.99), and Cisco Sd-wan Vsmart Controller Firmware are affected.
4
How can an unauthenticated remote attacker exploit CVE-2021-1301?
An unauthenticated remote attacker can execute attacks against an affected device.
5
Where can I find more information about CVE-2021-1301?
You can find more information about CVE-2021-1301 in the Cisco Security Advisory.