CVE-2020-3180: Cisco SD-WAN

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.

Affected products

  • Cisco SD-WAN: from 18.3.0, before 18.3.6 (fixed in 18.3.6); from 18.4.0, before 18.4.5 (fixed in 18.4.5); from 19.2.0, before 19.2.2 (fixed in 19.2.2)

Published 2020-07-16. Last modified 2026-06-17.