• About
  • Advertise
  • Careers
  • Contact
Friday, March 24, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

Cisco addresses multiple issues in its SD-WAN product

by Cyber360 News
March 19, 2020
in Security
0
Cisco addresses multiple issues in its SD-WAN product
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Cisco has addressed a total of five vulnerabilities in its SD-WAN solution, including three high severity flaws.

Cisco has addressed five vulnerabilities in its SD-WAN solution, including three high severity flaws.

The vulnerabilities could be exploited by attackers to make unauthorized changes to the system, inject arbitrary commands that are executed with root permissions, and escalate privileges to root.

The flaws are all caused by insufficient input validation, they were discovered by experts at Orange Group.

Three high-severity vulnerabilities, tracked as CVE-2020-3265, CVE-2020-3266, CVE-2020-3264, could be exploited by a local, authenticated attackerby sending specially crafted requests or specially crafted input to the targeted system.

The vulnerabilities impact several Cisco products running an SD-WAN version prior to 19.2.2. The list of affected products includes vBond Orchestrator, vEdge routers, vManage network management software, and vSmart controller software.

The tech giant also addressed a stored Cross-Site Scripting flaw (CVE-2019-16010) and a SQL Injection flaw (CVE-2019-16012) in the SD-WAN Solution vManage.

Both issues could be remotely exploited by an authenticated attacker.

The good news is that the company is not aware of attacks in the wild that exploited the above flaws.

Pierluigi Paganini

(SecurityAffairs – CISCO SD-WAN, cyber security)



Share On


Cyber360 News

Cyber360 News

Next Post
The administrator of the sinister dark web site has been arrested as well.

The administrator of the sinister dark web site has been arrested as well.

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In