CVE-2020-3180
published 2020-07-16CVE-2020-3180: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.5th percentile
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | sd-wan | >= 18.3.0 < 18.3.6 | 18.3.6 |
| cisco | sd-wan | >= 18.4.0 < 18.4.5 | 18.4.5 |
| cisco | sd-wan | >= 19.2.0 < 19.2.2 | 19.2.2 |
| cisco | sd-wan_solution | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco SD-WAN Solution Software Static Credentials Vulnerability
vendor_cisco·2020-07-15·CVSS 8.4
CVE-2020-3180 [HIGH] CWE-264 Cisco SD-WAN Solution Software Static Credentials Vulnerability
Cisco SD-WAN Solution Software Static Credentials Vulnerability
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges.
The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps
Cisco
Cisco SD-WAN Solution Software Static Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3180 Cisco SD-WAN Solution Software Static Credentials Vulnerability
CVE-2020-3180: Cisco SD-WAN Solution Software Static Credentials Vulnerability
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-264, CWE-264
Bug IDs: CSCvi59720, CSCvi85074
GHSA
GHSA-9f2x-x83c-j7w8: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that
ghsa_unreviewed·2022-05-24
CVE-2020-3180 [HIGH] CWE-522 GHSA-9f2x-x83c-j7w8: A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-16
Published