Man-in-the-middle attack in Cisco SD-WAN - CVE-2018-0434
Published: September 5, 2018 / Updated: September 6, 2018
Cisco SD-WAN
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct man-in-the-middle attack.
The vulnerability exists in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution due to insufficient certificate validation. A remote attacker can supply a specially crafted certificate, conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.