cisco-sa-sdw-mpls-infodisclos-MSSRFkZq: Cisco SD-WAN Software Information Disclosure Vulnerability
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient handling of malformed MPLS packets that are processed by a device that is running Cisco SD-WAN Software. An attacker could exploit this vulnerability by sending a crafted MPLS packet to an affected device that is running Cisco SD-WAN Software or Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to gain unauthorized access to sensitive information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-mpls-infodisclos-MSSRFkZq
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-sdw-mpls-infodisclos-MSSRFkZq?
The severity of cisco-sa-sdw-mpls-infodisclos-MSSRFkZq is rated as a high risk due to the potential for unauthorized information disclosure.
How do I fix cisco-sa-sdw-mpls-infodisclos-MSSRFkZq?
To fix cisco-sa-sdw-mpls-infodisclos-MSSRFkZq, upgrade to the latest version of Cisco SD-WAN Software as recommended by Cisco.
What impact does cisco-sa-sdw-mpls-infodisclos-MSSRFkZq have on systems?
The impact of cisco-sa-sdw-mpls-infodisclos-MSSRFkZq includes unauthorized access to sensitive data stored in MPLS buffer memory.
Which versions of Cisco SD-WAN Software are affected by cisco-sa-sdw-mpls-infodisclos-MSSRFkZq?
The affected versions of Cisco SD-WAN Software include 20.5, 20.4, 20.3, 19.2, and 18.4 up to their respective latest patch levels.
Who can exploit cisco-sa-sdw-mpls-infodisclos-MSSRFkZq?
An unauthenticated, remote attacker can exploit cisco-sa-sdw-mpls-infodisclos-MSSRFkZq to gain unauthorized access to information.