Lucene search

K
cvelistCiscoCVELIST:CVE-2018-15387
HistoryOct 05, 2018 - 2:00 p.m.

CVE-2018-15387 Cisco SD-WAN Solution Certificate Validation Bypass Vulnerability

2018-10-0514:00:00
CWE-20
cisco
www.cve.org
2

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

55.4%

A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to an affected device, bypassing the certificate validation. An exploit could allow an attacker to deploy a crafted system image.

CNA Affected

[
  {
    "product": "Cisco SD-WAN Solution",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

55.4%

Related for CVELIST:CVE-2018-15387