6.5

CVE-2020-3372

Cisco SD-WAN vManage Software Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume excessive system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to the affected web-based management interface. A successful exploit could allow the attacker to exhaust system memory, which could cause the system to stop processing new connections and could result in a DoS condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Sd-wan Firmware Version < 19.2.3
   Cisco ≫ 1100-4g Integrated Services Router Version -
   Cisco ≫ 1100-4gltegb Integrated Services Router Version -
   Cisco ≫ 1100-4gltena Integrated Services Router Version -
   Cisco ≫ 1100-6g Integrated Services Router Version -
   Cisco ≫ Vedge 100 Version -
   Cisco ≫ Vedge 1000 Version -
   Cisco ≫ Vedge 100b Version -
   Cisco ≫ Vedge 100m Version -
   Cisco ≫ Vedge 100wm Version -
   Cisco ≫ Vedge 2000 Version -
   Cisco ≫ Vedge 5000 Version -
Cisco ≫ Sd-wan Firmware Version >= 20.1.0 < 20.1.12
   Cisco ≫ 1100-4g Integrated Services Router Version -
   Cisco ≫ 1100-4gltegb Integrated Services Router Version -
   Cisco ≫ 1100-4gltena Integrated Services Router Version -
   Cisco ≫ 1100-6g Integrated Services Router Version -
   Cisco ≫ Vedge 100 Version -
   Cisco ≫ Vedge 1000 Version -
   Cisco ≫ Vedge 100b Version -
   Cisco ≫ Vedge 100m Version -
   Cisco ≫ Vedge 100wm Version -
   Cisco ≫ Vedge 2000 Version -
   Cisco ≫ Vedge 5000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.56
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
Cisco PSIRT 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-emvman-3y6LuTcZ
Vendor Advisory