7.8

CVE-2019-1648

Cisco SD-WAN Solution Privilege Escalation Vulnerability

A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a crafted file to the directory where the user group configuration is located in the underlying operating system. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Vedge 100 Firmware
   Cisco ≫ Vedge 100 Version -
Cisco ≫ Vedge 1000 Firmware
   Cisco ≫ Vedge 1000 Version -
Cisco ≫ Vedge 2000 Firmware
   Cisco ≫ Vedge 2000 Version -
Cisco ≫ Vedge 5000 Firmware
   Cisco ≫ Vedge 5000 Version -
Cisco ≫ Sd-wan Version < 18.4.0
Cisco ≫ Vbond Orchestrator Version -
Cisco ≫ Vsmart Controller Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.288
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Cisco PSIRT 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/106719
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escal
Vendor Advisory