CVE-2018-0346 describes a denial-of-service vulnerability in the Zero Touch Provisioning service of Cisco SD-WAN Solution products, including vBond Orchestrator, vManage, and vSmart Controller software, running releases prior to 18.3.0. The vulnerability stems from incorrect bounds checks, leading to a buffer overflow when processing specially crafted packets. An unauthenticated, remote attacker can exploit this by sending malicious packets directly to an affected device, causing it to reload and resulting in a temporary denial of service. The vulnerability has a CVSSv3 score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability, requiring no privileges or user interaction. While the EPSS score is very low, suggesting minimal exploitability in the wild, the FAUCET Risk Score is moderate at 51/100. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, aligning with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vbond_orchestrator:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vedge-plus:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vedge-pro:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vmanage_network_management:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vsmart_controller:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.