CVE-2018-15387

CRITICAL

Cisco SD-WAN Solution - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to an affected device, bypassing the certificate validation. An exploit could allow an attacker to deploy a crafted system image.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105509

Scores

CVSS v3 9.8
EPSS 0.0110
EPSS Percentile 61.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20 CWE-295
Status published
Products (2)
cisco/sd-wan 18.3.0
cisco/sd-wan 17.2.0 - 17.2.8
Published Oct 05, 2018
Tracked Since Feb 18, 2026