ZeroHour

CVE-2020-3265

CVSS 3.1
7.8 high
EPSS
<1%p32
Published
()
Modified
Description

A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain root-level privileges.

Vendors
cisco
Products
sd-wan firmware
Weakness
CWE-264, CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news