Cisco Addressed Multiple High-Risk Vulnerabilities In SD-WAN Solution

Cisco have addressed multiple high-severity vulnerabilities in its SD-WAN Solution. The first of these vulnerabilities is a command injection vulnerability (CVE-2020-3266) with a CVSS score of 7.8. As elaborated in an advisory, a local attacker could exploit the bug to inject and execute arbitrary commands with root privileges. Explaining further about the flaw, the advisory reads All these vulnerabilities primarily affected Cisco products running on earlier versions of SD-WAN Solution. These include vBond Orchestrator Software, vEdge Routers (100 Series, 1000 Series, 2000 Series, and 5000 Series), vEdge Cloud Router Platform, vSmart Controller Software, and vManage Network Management System. Upon detecting the bugs, Cisco patched them with the release of Cisco SD-WAN Solution software Release 19.2.2. Users of the respective devices must ensure that their systems are running on the latest version with the fixes. Cisco acknowledged the Orange Group for reporting all these vulnerabilities. Whereas they also confirmed no detection of active exploitation of the bugs. Let us know your thoughts in the comments.

Spotlight

Spotlight

Related News