#VU13221 Privilege escalation in Cisco Wide Area Application Services - CVE-2018-0352
Published: June 6, 2018 / Updated: June 7, 2018
Cisco Wide Area Application Services
Cisco Systems, Inc
Description
The vulnerability allows a local high-privileged ttacker to gain elevated privileges the target system.
The vulnerability exists n the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software due to insufficient validation of script files executed in the context of the Disk Check Tool. A local attacker with super user privileges (level 15) can replace one script file with a malicious script file while the affected tool is running, gain root-level privileges and take full control of the device.