Privilege escalation in Cisco SD-WAN - CVE-2019-1650

 

Privilege escalation in Cisco SD-WAN - CVE-2019-1650

Published: January 25, 2019


Vulnerability identifier: #VU17224
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1650
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to gain elevated privileges on an affected device.

The vulnerability exists due to improper input validation of the save command in the CLI of the affected software. A remote authenticated attacker can modify the save command in the CLI of an affected device, overwrite arbitrary files on the underlying operating system of an affected device and escalate their privileges to the root user.


Affected software

Cisco SD-WAN

How to mitigate CVE-2019-1650

Update to version 18.4.0.

Cisco SD-WAN - update to 18.4.0

External References

Related Security Bulletins