Input validation error in Cisco SD-WAN vEdge 5000 Series Routers and Cisco SD-WAN vEdge Cloud Router - CVE-2020-3385
Published: July 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on an affected system.
The vulnerability exists due to insufficient validation of user-supplied input in the deep packet inspection (DPI) engine. A remote attacker on the local network can send specially crafted packets and cause a denial of service condition on the target system.
Affected software
Cisco SD-WAN vEdge Cloud Router
How to mitigate CVE-2020-3385
Cisco SD-WAN vEdge Cloud Router - addressed in versions 18.4.5, 19.2.3, 20.1.1