CVE-2021-34727
Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 2.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
23 sep 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Cisco · Cisco IOS XE SD-WAN Software¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →