CVE-2020-3372
Cisco SD-WAN vManage Software Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume excessive system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to the affected web-based management interface. A successful exploit could allow the attacker to exhaust system memory, which could cause the system to stop processing new connections and could result in a DoS condition.
Una vulnerabilidad en la interfaz de administración basada en web de Cisco SD-WAN vManage Software podría permitir a un atacante remoto autenticado consumir memoria excesiva del sistema y causar una condición de denegación de servicio (DoS) sobre un sistema afectado. La vulnerabilidad es debido a una gestión de memoria ineficiente. Un atacante podría explotar esta vulnerabilidad mediante el envío de una gran cantidad de peticiones HTTP diseñadas a la interfaz de administración basada en web afectada. Una explotación con éxito podría permitir a un atacante agotar la memoria del sistema, lo que podría causar que el sistema deje de procesar nuevas conexiones y podría resultar en una condición DoS
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-07-16 CVE Published
- 2023-03-07 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-emvman-3y6LuTcZ | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g Integrated Services Router Search vendor "Cisco" for product "1100-4g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4gltegb Integrated Services Router Search vendor "Cisco" for product "1100-4gltegb Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4gltena Integrated Services Router Search vendor "Cisco" for product "1100-4gltena Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-6g Integrated Services Router Search vendor "Cisco" for product "1100-6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100 Search vendor "Cisco" for product "Vedge 100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 1000 Search vendor "Cisco" for product "Vedge 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100b Search vendor "Cisco" for product "Vedge 100b" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100m Search vendor "Cisco" for product "Vedge 100m" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100wm Search vendor "Cisco" for product "Vedge 100wm" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 2000 Search vendor "Cisco" for product "Vedge 2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 19.2.3 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 19.2.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 5000 Search vendor "Cisco" for product "Vedge 5000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g Integrated Services Router Search vendor "Cisco" for product "1100-4g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4gltegb Integrated Services Router Search vendor "Cisco" for product "1100-4gltegb Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4gltena Integrated Services Router Search vendor "Cisco" for product "1100-4gltena Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-6g Integrated Services Router Search vendor "Cisco" for product "1100-6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100 Search vendor "Cisco" for product "Vedge 100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 1000 Search vendor "Cisco" for product "Vedge 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100b Search vendor "Cisco" for product "Vedge 100b" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100m Search vendor "Cisco" for product "Vedge 100m" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100wm Search vendor "Cisco" for product "Vedge 100wm" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 2000 Search vendor "Cisco" for product "Vedge 2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | >= 20.1.0 < 20.1.12 Search vendor "Cisco" for product "Sd-wan Firmware" and version " >= 20.1.0 < 20.1.12" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 5000 Search vendor "Cisco" for product "Vedge 5000" | - | - |
Safe
|