CVE-2020-3385

A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted packets through an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:vedge_5000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:cisco:vedge_cloud_router:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:30

Type Values Removed Values Added
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vedgfpdos-PkqQrnwV - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vedgfpdos-PkqQrnwV - Vendor Advisory

Information

Published : 2020-07-16 18:15

Updated : 2024-11-21 05:30


NVD link : CVE-2020-3385

Mitre link : CVE-2020-3385

CVE.ORG link : CVE-2020-3385


JSON object : View

Products Affected

cisco

  • vedge_cloud_router
  • vedge_5000
  • sd-wan_firmware
CWE
CWE-371

State Issues

NVD-CWE-noinfo