Denial of Service Vulnerability in Cisco SD-WAN Solution
CVE-2018-0346
7.5HIGH
What is CVE-2018-0346?
A flaw in the Zero Touch Provisioning service of Cisco's SD-WAN Solution allows unauthenticated remote attackers to exploit incorrect bounds checks in packet handling. Attackers can send specifically crafted packets to an affected device, triggering a buffer overflow that causes the device to reload. This results in a temporary denial of service, impacting the availability of services. It is important to note that exploitation occurs solely through traffic intended for the vulnerable device and not through passing traffic. Affected products are any Cisco devices operating pre-18.3.0 versions of the SD-WAN Solution.
Affected Version(s)
Cisco SD-WAN Solution unknown Cisco SD-WAN Solution unknown