7.4

CVE-2018-0434

Cisco SD-WAN Solution Certificate Validation Vulnerability

A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Vedge 100 Firmware Version < 18.3.0
   Cisco ≫ Vedge 100 Version -
Cisco ≫ Vedge 1000 Firmware Version < 18.3.0
   Cisco ≫ Vedge 1000 Version -
Cisco ≫ Vedge 2000 Firmware Version < 18.3.0
   Cisco ≫ Vedge 2000 Version -
Cisco ≫ Vedge 5000 Firmware Version < 18.3.0
   Cisco ≫ Vedge 5000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.538
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.4 2.2 5.2
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://www.securityfocus.com/bid/105294
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-sd-wan-validation
Vendor Advisory