cbcvebase.
CVE-2020-3180
published 2020-07-16

CVE-2020-3180: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_sd-wan_vmanage
ciscosd-wan>= 18.3.0 < 18.3.618.3.6
ciscosd-wan>= 18.4.0 < 18.4.518.4.5
ciscosd-wan>= 19.2.0 < 19.2.219.2.2
ciscosd-wan_solution