• Linkedin
JOS SG
  • Home
  • Solutions

      Consultancy, Deployment & Migration

      • Everything-as-a-Services
      • Enterprise Security Services
      • Enterprise Application Services
      • SharePoint Services
      • Business & Robotic Process Automation
      • VAPT Security Consultancy

      IT-as-a-Service

      • Hardware Maintenance Service
      • System Maintenance Services
      • Managed Services

      Digital Transformation

      • Empower your Future Workforce
      • Future Workplace
      • Transform with IT
      • Retail IT Transformation
      • Agreements Automation
  • Resources
  • Contact Us
SolarWinds Security Advisory
January 6, 2021
SonicWall Security Advisory
February 11, 2021

Cisco SD-WAN Security Advisory

What happened?

The recent talk of the town is the critical vulnerabilities in Cisco SD-WAN software. These vulnerabilities allow unauthenticated attackers to perform remote command injection attacks against devices with root privileges. Since there are no workarounds to address these vulnerabilities, here are the important updates for the affected devices.

Current Remediation

Cisco is requesting customers with the affected products below to upgrade to an appropriate fixed software release for remediating the issue.

  • Cisco SD-WAN vManage Authorization Bypass Vulnerabilities
  • Cisco SD-WAN Buffer Overflow Vulnerabilities
  • Cisco SW-WAN Command Injection Vulnerabilities
  • Cisco SD-WAN Denial of Service Vulnerabilities
Cisco SD-WAN Release First Fixed Release for These Vulnerabilities First Fixed Release for All Vulnerabilities Described in the Collection of Advisories
Earlier than 18.3
18.3, 18.4
19.2, 19.3
Migrate to a fixed release.
Migrate to a fixed release.
20.1
20.1.2
Migrate to a fixed release.
20.3
20.3.2
20.3.2
20.4
20.4.1
20.4.1
Workaround

The fixed software versions are necessary to be applied. If you are unable to apply due to environmental restrictions, please review the below:

  • Work with your MSSP partner to raise your CISCO device to high alert. Continue to monitor possible attack event.
  • Consider adding affected CISCO devices to be managed by your Privileged Access Management (PAM) solutions.
  • Forward access logs to a centralised log collector for analysis if you do not have a PAM solution.
  • hBe prudent and review any root access attempt on your CISCO affected devices.
Known affected products

The vulnerabilities can affect the following Cisco products, if they are running a vulnerable release of Cisco SD-WAN software. 

  • SD-WAN vBond Orchestrator Software
  • SD-WAN vEdge Cloud Routers
  • SD-WAN vEdge Routers
  • SD-WAN vManage Software
  • SD-WAN vSmart Controller Software

1 Feb 2021 | Original articles from Cisco

RELATED POSTS

SolarWinds Security Advisory

Read More »
January 6, 2021

Microsoft Security Advisory

Read More »
March 11, 2021

F5 Networks Security Advisory

Read More »
March 26, 2021
Share
75

Blog Categories

Enjoy Peace of Mind with JOS IT-as-a-Ser

https://www.jos.com.sg/wp-content/uploads/2022/06/JOS-ITaaS-1.mp4

Recent Post

  • SUTD gets a SPEED bump with JOS November 9, 2023
  • JOS Services Brochure September 14, 2023
  • JOS Enterprise Applications Brochure September 14, 2023
  • JOS Enterprise Security Brochure September 14, 2023
  • JOS Big Data & Analytics Brochure September 14, 2023

Company

  • About Us
  • Contact Us

Solutions

  • Cloud
  • Enterprise Security
  • Enterprise Applications
  • SharePoint Services
  • Automation Services

IT-as-a-Service

  • About ITaaS
  • Hardware Maintenance
  • System Maintenance
  • Managed Services

Resources

  • Brochures
  • Infographic
  • Videos
  • Articles
  • Security Advisory

JOS (SG) Pte. Ltd.

Copyright © 2023 JOS (SG) Pte. Ltd. All rights reserved.

 Privacy Policy | Terms & Conditions

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of all the cookies. However, you may visit your cookie settings to provide a controlled consent.
Read MoreAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT