CVE-2020-3385: Cisco SD-WAN Firmware

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted packets through an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition.

Affected products

  • Cisco SD-WAN Firmware: up to and including 18.3.0; from 18.4.0, before 18.4.5 (fixed in 18.4.5); from 19.2.0, before 19.2.3 (fixed in 19.2.3); from 19.3.0, before 20.1.1 (fixed in 20.1.1)
  • Cisco Vedge Cloud Router: affected versions not specified

Published 2020-07-16. Last modified 2026-06-17.