Cisco has addressed five vulnerabilities in its SD-WAN solution, including three high severity flaws.
The vulnerabilities could be exploited by attackers to make unauthorized changes to the system, inject arbitrary commands that are executed with root permissions, and escalate privileges to root.
The flaws are all caused by insufficient input validation, they were discovered by experts at Orange
Three high-severity vulnerabilities, tracked as CVE-2020-3265, CVE-2020-3266, CVE-2020-3264, could be exploited by a local, authenticated
The vulnerabilities impact several Cisco products running an SD-WAN version prior to 19.2.2. The list of affected products includes
The tech giant also addressed a stored Cross-Site Scripting flaw (CVE-2019-16010) and a SQL Injection flaw (CVE-2019-16012) in the SD-WAN Solution
Both issues could be remotely exploited by an authenticated attacker.
The good news is that the company is not aware of attacks in the wild that exploited the above flaws.
(SecurityAffairs – CISCO SD-WAN, cyber security)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.