Command injection in Cisco SD-WAN - CVE-2018-0433
Published: September 6, 2018 / Updated: September 6, 2018
Cisco SD-WAN
Detailed vulnerability description
The vulnerability allows a local attacker to execute arbitrary commands.
The vulnerability exists in the command-line interface (CLI) in the Cisco SD-WAN Solution due to insufficient input validation. A local attacker can submit specially crafted input to the CLI utility to inject and execute commands with root privileges.