Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3387

Опубликовано: 16 июл. 2020
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to access the software and execute commands they should not be authorized to execute.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия до 18.3.0 (включая)
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия от 18.4.0 (включая) до 19.2.3 (исключая)
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
Версия от 19.3.0 (включая) до 20.1.1.1 (исключая)

Одно из

cpe:2.3:h:cisco:1100-4g_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltegb_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltena_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-6g_integrated_services_router:-:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.45692
Средний

7.5 High

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to access the software and execute commands they should not be authorized to execute.

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость веб-интерфейса vManage программно-определяемой сети Cisco SD-WAN, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 98%
0.45692
Средний

7.5 High

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20
CWE-20