5.4

CVE-2021-1466

A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, resulting in a denial of service (DoS) condition.
The vulnerability is due to incomplete bounds checks for data that is provided to the vDaemon service of an affected system. An attacker could exploit this vulnerability by sending malicious data to the vDaemon listening service on the affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could allow the attacker to cause the vDaemon listening service to reload and result in a DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CiscoCatalyst Sd-wan Manager Version17.2.4
CiscoCatalyst Sd-wan Manager Version17.2.5
CiscoCatalyst Sd-wan Manager Version17.2.6
CiscoCatalyst Sd-wan Manager Version17.2.7
CiscoCatalyst Sd-wan Manager Version17.2.8
CiscoCatalyst Sd-wan Manager Version17.2.9
CiscoCatalyst Sd-wan Manager Version17.2.10
CiscoCatalyst Sd-wan Manager Version18.2.0
CiscoCatalyst Sd-wan Manager Version18.3.0
CiscoCatalyst Sd-wan Manager Version18.3.1
CiscoCatalyst Sd-wan Manager Version18.3.1.1
CiscoCatalyst Sd-wan Manager Version18.3.3
CiscoCatalyst Sd-wan Manager Version18.3.3.1
CiscoCatalyst Sd-wan Manager Version18.3.4
CiscoCatalyst Sd-wan Manager Version18.3.5
CiscoCatalyst Sd-wan Manager Version18.3.6
CiscoCatalyst Sd-wan Manager Version18.3.6.1
CiscoCatalyst Sd-wan Manager Version18.3.7
CiscoCatalyst Sd-wan Manager Version18.3.8
CiscoCatalyst Sd-wan Manager Version18.4.0
CiscoCatalyst Sd-wan Manager Version18.4.0.1
CiscoCatalyst Sd-wan Manager Version18.4.1
CiscoCatalyst Sd-wan Manager Version18.4.3
CiscoCatalyst Sd-wan Manager Version18.4.4
CiscoCatalyst Sd-wan Manager Version18.4.302
CiscoCatalyst Sd-wan Manager Version18.4.303
CiscoCatalyst Sd-wan Manager Version19.0.0
CiscoCatalyst Sd-wan Manager Version19.0.1a
CiscoCatalyst Sd-wan Manager Version19.1.0
CiscoCatalyst Sd-wan Manager Version19.2.0
CiscoCatalyst Sd-wan Manager Version19.2.1
CiscoCatalyst Sd-wan Manager Version19.2.2
CiscoCatalyst Sd-wan Manager Version19.2.097
CiscoCatalyst Sd-wan Manager Version19.2.098
CiscoCatalyst Sd-wan Manager Version19.2.099
CiscoCatalyst Sd-wan Manager Version19.3.0
CiscoCatalyst Sd-wan Manager Version20.1.1
CiscoCatalyst Sd-wan Manager Version20.1.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.35
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
psirt@cisco.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.