Buffer overflow in Cisco SD-WAN vEdge Routers and Cisco SD-WAN vEdge Cloud Router - CVE-2021-1511
Published: May 6, 2021
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in forwarding error correction in Cisco SD-WAN vEdge Software. A remote user authenticated to the device through IPsec can send specially crafted traffic to the system, trigger memory corruption and perform a denial of service (DoS) attack.
Affected software
Cisco SD-WAN vEdge Cloud Router
How to mitigate CVE-2021-1511
Cisco SD-WAN vEdge Cloud Router - addressed in versions 20.4.1, 20.5.1