Privilege escalation in Cisco SD-WAN - CVE-2018-0432
Published: September 6, 2018
Cisco SD-WAN
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to gain elevated privileges.
The vulnerability exists in the error reporting feature of the Cisco SD-WAN Solution due to improper validation of certain parameters included within the error reporting application configuration. A remote attacker can send a specially crafted command to the error reporting feature, gain root-level privileges and take full control of the device.