A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to an affected device, bypassing the certificate validation. An exploit could allow an attacker to deploy a crafted system image.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco Sd Wan
APPCisco18.3.017.2.0 – 17.2.8 (excl.)
Related vulnerabilities
Obejście autoryzacji w Cisco SD-WAN vManage — eskalacja uprawnień
Buffer overflow w Cisco SD-WAN — zdalne wykonanie kodu jako root
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain eleva...
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauth...
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to g...