CVE Database
/

CVE-2020-26071

Back to search

CVE-2020-26071

Published: Nov 18, 2024

Modified: Nov 18, 2024

PUBLISHED

CVSS v3.1

8.4

HIGH

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation for specific commands. An attacker could exploit this vulnerability by including crafted arguments to those specific commands. A successful exploit could allow the attacker to create or overwrite arbitrary files on the affected device, which could result in a DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

VendorProductVersions

Cisco

Cisco Catalyst SD-WAN Manager

affected
20.1.12
affected
19.2.1
affected
18.4.4
affected
18.4.5
affected
20.1.1.1

+37 more versions

Cisco

Cisco SD-WAN vContainer

affected
18.4.5
affected
20.1.12
affected
18.3.6
affected
19.2.1
affected
19.3.0

+29 more versions

Cisco

Cisco SD-WAN vEdge Cloud

affected
19.2.1
affected
20.1.12
affected
18.4.4
affected
19.3.0
affected
18.3.8

+30 more versions

Cisco

Cisco SD-WAN vEdge Router

affected
18.4.303
affected
18.3.7
affected
19.3.0
affected
18.2.0
affected
20.1.12

+33 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H/RL:X/RC:X/E:X

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now