CVE-2021-1300

CRITICAL

Cisco Ios XE Sd-wan - Memory Corruption

Title source: rule
STIX 2.1

Description

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0088
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (8)
cisco/catalyst_sd-wan_manager
cisco/ios_xe_sd-wan
cisco/sd-wan_firmware 18.3.8
cisco/sd-wan_firmware 18.4.4
cisco/sd-wan_firmware 19.2.1
cisco/sd-wan_firmware 19.2.99
cisco/sd-wan_vbond_orchestrator
cisco/sd-wan_vsmart_controller_firmware
Published Jan 20, 2021
Tracked Since Feb 18, 2026