Cisco SD-WAN vEdge是美国思科(Cisco)公司的是一款路由器。该设备可为思科SD-WAN解决方案提供基本WAN,安全性和多云功能。 Cisco SD-WAN vEdge 存在输入验证错误漏洞,该漏洞源于网络系统或产品未对输入的数据进行正确的验证。攻击者可以通过制作具有特定特征的恶意TCP数据包并将其发送到目标设备来利用此漏洞绕过L3和L4流量过滤器,并将任意数据包注入网络。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco SD-WAN Solution | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-3603 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3573 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3593 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3594 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3600 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3604 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3595 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3574 | 7.5 HIGH | Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability |
| CVE-2020-3588 | 7.3 HIGH | Cisco Webex Meetings Desktop App Arbitrary Code Execution Vulnerability |
| CVE-2020-3556 | 7.3 HIGH | Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability |
| CVE-2020-27129 | 6.7 MEDIUM | Cisco SD-WAN vManage Software Command Injection Vulnerability |
| CVE-2020-3592 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Authorization Bypass Vulnerability |
| CVE-2020-26084 | 6.5 MEDIUM | Cisco Edge Fog Fabric Resource Exposure Vulnerability |
| CVE-2020-27128 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability |
| CVE-2020-3590 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3587 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3371 | 6.3 MEDIUM | Cisco Integrated Management Controller Command Injection Vulnerability |
| CVE-2020-3551 | 6.1 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
| CVE-2020-27123 | 5.5 MEDIUM | Cisco AnyConnect Secure Mobility Client for Windows Arbitrary File Read Vulnerability |
| CVE-2020-26083 | 4.8 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet