7.5

CVE-2021-1510

Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Data is provided by the National Vulnerability Database (NVD)
CiscoVedge 100 Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 100 Version-
CiscoVedge 100 Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 100 Version-
CiscoVedge 100 Firmware Version19.2.99
   CiscoVedge 100 Version-
CiscoVedge 1000 Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 1000 Version-
CiscoVedge 1000 Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 1000 Version-
CiscoVedge 1000 Firmware Version19.2.99
   CiscoVedge 1000 Version-
CiscoVedge 100b Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 100b Version-
CiscoVedge 100b Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 100b Version-
CiscoVedge 100b Firmware Version19.2.99
   CiscoVedge 100b Version-
CiscoVedge 100m Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 100m Version-
CiscoVedge 100m Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 100m Version-
CiscoVedge 100m Firmware Version19.2.99
   CiscoVedge 100m Version-
CiscoVedge 100wm Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 100wm Version-
CiscoVedge 100wm Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 100wm Version-
CiscoVedge 100wm Firmware Version19.2.99
   CiscoVedge 100wm Version-
CiscoVedge 2000 Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 2000 Version-
CiscoVedge 2000 Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 2000 Version-
CiscoVedge 2000 Firmware Version19.2.99
   CiscoVedge 2000 Version-
CiscoVedge 5000 Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 5000 Version-
CiscoVedge 5000 Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 5000 Version-
CiscoVedge 5000 Firmware Version19.2.99
   CiscoVedge 5000 Version-
CiscoVedge 100b Firmware Version >= 20.4 < 20.4.1
   CiscoVedge 100b Version-
CiscoVedge 100b Firmware Version >= 20.5 < 20.5.1
   CiscoVedge 100b Version-
CiscoVedge 100b Firmware Version19.2.99
   CiscoVedge 100b Version-
CiscoVedge Cloud Firmware Version >= 20.4 < 20.4.1
   CiscoVedge Cloud Version-
CiscoVedge Cloud Firmware Version >= 20.5 < 20.5.1
   CiscoVedge Cloud Version-
CiscoVedge Cloud Firmware Version19.2.99
   CiscoVedge Cloud Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.91% 0.737
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
psirt@cisco.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.