CVE-2021-1241 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Cisco Sd-wan Solution
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory BufferCWE-20 — Improper Input ValidationCWE-787 — Out-of-bounds WriteCWE-1241 — Use of Predictable Algorithm in Random Number GeneratorCWE-330 — Use of Insufficiently Random ValuesCWE-331 — Insufficient Entropy7 documents6 sources
Severity
7.5HIGHNVD
CNA8.6
EPSS
0.6%
top 30.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateNov 16
Description
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
4GHSA▶
GHSA-h93f-69cr-g7fq: Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against a↗2022-05-24
📋Vendor Advisories
1🕵️Threat Intelligence
1Talos▶
Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station↗2021-05-24