cisco-sa-sdwan-bufovulns-B5NrSHbj: Cisco SD-WAN Buffer Overflow Vulnerabilities

Published Jan 20, 2021
·
Updated

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-bufovulns-B5NrSHbj

Credit

These vulnerabilities were found by James Spadaro(Cisco during internal security testing)

Affected Software

3 affected componentsFixes available
Cisco SD-WAN Releases=20.4, <20.4.1, =20.3, <20.3.1, >=19.3, <=20.1, <20.1.1, =19.2, <19.2.2, >=.3, <18, =18.3, <=18.4, <18.4.5
20.4.120.3.120.1.119.2.218.4.5
Cisco IOS XE SD-WAN Releases>=16.9, =16.10, =16.11, <=16.12, <16.12.4
16.12.4
Cisco IOS XE Universal Releases=17.4, <17.4.1, =17.3, <17.3.1, =17.2, <17.2.1
17.4.117.3.117.2.1

Event History

Jan 20, 2021
Advisory Published
via Cisco·04:00 PM

Child vulnerabilities

Contains the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of cisco-sa-sdwan-bufovulns-B5NrSHbj?

The severity of cisco-sa-sdwan-bufovulns-B5NrSHbj is classified as high due to the potential for unauthenticated remote code execution.

2

How do I fix cisco-sa-sdwan-bufovulns-B5NrSHbj?

To fix cisco-sa-sdwan-bufovulns-B5NrSHbj, you should apply the available software updates provided by Cisco for the affected SD-WAN and IOS XE versions.

3

Which Cisco products are affected by cisco-sa-sdwan-bufovulns-B5NrSHbj?

The affected products in cisco-sa-sdwan-bufovulns-B5NrSHbj include Cisco SD-WAN Releases, IOS XE SD-WAN Releases, and IOS XE Universal Releases.

4

Can attackers exploit cisco-sa-sdwan-bufovulns-B5NrSHbj without authentication?

Yes, attackers can exploit cisco-sa-sdwan-bufovulns-B5NrSHbj without authentication, allowing them to execute arbitrary commands.

5

What are the recommended actions for users of cisco-sa-sdwan-bufovulns-B5NrSHbj?

Users of cisco-sa-sdwan-bufovulns-B5NrSHbj should immediately assess their environments and implement the recommended software updates to mitigate the vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203