CVE-2024-20496: Cisco SD-WAN Vedge Cloud

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.

Affected products

  • Cisco Cisco SD-WAN Vedge Cloud: version 19.2.1 only; version 20.1.12 only; version 18.4.4 only; version 19.3.0 only; version 18.3.8 only; version 19.2.2 only; …
  • Cisco Cisco SD-WAN Vedge Router: version 18.4.303 only; version 18.3.7 only; version 19.3.0 only; version 18.2.0 only; version 20.1.12 only; version 19.2.099 only; …

Published 2024-09-25. Last modified 2026-06-17.