Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-0346

EPSS 0.48% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-0346

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the Zero Touch Provisioning service of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checks for certain values in packets that are sent to the Zero Touch Provisioning service of the affected software. An attacker could exploit this vulnerability by sending malicious packets to the affected software for processing. When the software processes the packets, a buffer overflow condition could occur and cause an affected device to reload. A successful exploit could allow the attacker to cause a temporary DoS condition while the device reloads. This vulnerability can be exploited only by traffic that is destined for an affected device. It cannot be exploited by traffic that is transiting a device. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vManage Network Management Software, vSmart Controller Software. Cisco Bug IDs: CSCvi69914.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco SD-WAN Solution 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco vBond Orchestrator Software、vManage Network Management Software和Smart Controller Software都是美国思科(Cisco)公司的产品。Cisco vBond Orchestrator Software和vManage Network Management Software都是网络管理软件。Smart Controller Software是一套智能网络控制软件。SD-WAN Solution是运行在其中的一套网络
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco SD-WAN Solution unknown Cisco SD-WAN Solution unknown -

II. Public POCs for CVE-2018-0346

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0346

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-07-18 · 42 CVEs total

CVE-2018-14389joyplus-cms SQL注入漏洞
CVE-2018-0396Cisco Unified Communications Manager IM and Presence Service Software 跨站脚本漏洞
CVE-2018-0398Cisco Finesse 安全漏洞
CVE-2018-0399Cisco Finesse 信息泄露漏洞
CVE-2018-0400Cisco Unified Contact Center Express 跨站脚本漏洞
CVE-2018-0401Cisco Unified Contact Center Express 跨站脚本漏洞
CVE-2018-0402Cisco Unified Contact Center Express 跨站请求伪造漏洞
CVE-2018-0403Cisco Unified Contact Center Express 信息泄露漏洞
CVE-2018-14364GitLab 安全漏洞
CVE-2018-14387WonderCMS 安全漏洞
CVE-2018-14388joyplus-cms 跨站脚本漏洞
CVE-2018-0394Cisco Cloud Services Platform 2100 输入验证漏洞
CVE-2018-12429JEESNS 跨站脚本漏洞
CVE-2018-14082PHP Scripts Mall JOB SITE 跨站脚本漏洞
CVE-2018-7546Kingsoft WPS Office 2016和Jinshan PDF 安全漏洞
CVE-2018-14380Graylog typeahead组件跨站脚本漏洞
CVE-2018-14381Pagekit 安全漏洞
CVE-2018-14382InstantSoft InstantCMS 跨站脚本漏洞
CVE-2018-2968Oracle Construction and Engineering Suite Primavera Unifier组件安全漏洞
CVE-2018-14371Eclipse Mojarra 路径遍历漏洞

Showing top 20 of 42 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-0346

No comments yet


Leave a comment