CVE-2020-3375

Description

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to information that they are not authorized to access, make changes to the system that they are not authorized to make, and execute commands on an affected system with privileges of the root user.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.992

Associated Vulnerability

VulnerabilityOS Platform
Cisco SD-WAN Solution Software Buffer Overflow Vulnerability For Cisco IOS XE SD-WAN Software 16.10NCM
Cisco SD-WAN Solution Software Buffer Overflow Vulnerability For Cisco IOS XE SD-WAN Software 16.11NCM
Cisco SD-WAN Solution Software Buffer Overflow Vulnerability For Cisco IOS XE SD-WAN Software 16.12NCM
Cisco SD-WAN Solution Software Buffer Overflow Vulnerability For Cisco IOS XE SD-WAN Software 16.9NCM
Improper Input Validation Vulnerability (CVE-2020-3375)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1703663Security Update for Cisco IOS XE SD-WAN Software 16.10 sdwan-20.4.1
PATCH-1703664Security Update for Cisco IOS XE SD-WAN Software 16.11 sdwan-20.4.1
PATCH-1703665Security Update for Cisco IOS XE SD-WAN Software 16.12 sdwan-20.4.1
PATCH-1703667Security Update for Cisco IOS XE SD-WAN Software 16.9 sdwan-20.4.1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234