#VU13942 Privilege escalation in Cisco SD-WAN - CVE-2018-0349
Published: July 20, 2018
Cisco SD-WAN
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.
The vulnerability exists in the Cisco SD-WAN Solution due to improper input validation of the request admin-tech command in the CLI. A remote authenticated attacker can modify the request admin-tech command in the CLI and overwrite arbitrary files on the underlying operating system to gain root privileges.