CVE-2020-3387: Cisco SD-WAN Firmware

High severity, CVSS 8.8. EPSS: 13% chance of exploitation in the next 30 days.

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An attacker could exploit this vulnerability by sending a crafted response to the Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to access the software and execute commands they should not be authorized to execute.

Affected products

  • Cisco SD-WAN Firmware: up to and including 18.3.0; from 18.4.0, before 19.2.3 (fixed in 19.2.3); from 19.3.0, before 20.1.1.1 (fixed in 20.1.1.1)

Published 2020-07-16. Last modified 2026-06-17.