Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1300


Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2021-01-20T20:15:16.800

Last Modified

2024-11-21T05:44:02.410

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xe_sd-wan - Yes
Operating System cisco sd-wan_firmware 18.3.8 Yes
Operating System cisco sd-wan_firmware 18.4.4 Yes
Operating System cisco sd-wan_firmware 19.2.1 Yes
Operating System cisco sd-wan_firmware 19.2.99 Yes
Operating System cisco sd-wan_vsmart_controller_firmware * Yes
Hardware cisco vedge_100_router - No
Hardware cisco vedge_1000_router - No
Hardware cisco vedge_100b_router - No
Hardware cisco vedge_100m_router - No
Hardware cisco vedge_100wm_router - No
Hardware cisco vedge_2000_router - No
Hardware cisco vedge_5000_router - No
Hardware cisco vedge_cloud_router - No
Application cisco catalyst_sd-wan_manager - Yes
Application cisco sd-wan_vbond_orchestrator - Yes

References