CVE-2020-3369
Summary
| CVE | CVE-2020-3369 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-16 18:15:00 UTC |
| Updated | 2020-07-24 15:21:00 UTC |
| Description | A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of FTP traffic. An attacker could exploit this vulnerability by sending crafted FTP packets through an affected device. A successful exploit could allow the attacker to make the device reboot continuously, causing a DoS condition. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Sd-wan Firmware | 19.2.0 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.097 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.098 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.1 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.0 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.097 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.098 | All | All | All |
| Operating System | Cisco | Sd-wan Firmware | 19.2.1 | All | All | All |
| Hardware | Cisco | Vedge 5000 | - | All | All | All |
| Hardware | Cisco | Vedge 5000 | - | All | All | All |
| Application | Cisco | Vedge Cloud Router | - | All | All | All |
| Application | Cisco | Vedge Cloud Router | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco SD-WAN vEdge Routers Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.