CVE-2018-0434 is a high-severity vulnerability in the Zero Touch Provisioning feature of Cisco SD-WAN Solution, affecting various vEdge routers and vManage. It allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data due to insufficient certificate validation. An attacker could exploit this by supplying a crafted certificate, enabling man-in-the-middle attacks to decrypt confidential information. The CVSS score is 7.4 (High), indicating a network attack vector with high impact on confidentiality and integrity, but high attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vmanage_network_management_system:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.