Remote Command Injection Vulnerability in Cisco SD-WAN Solution
CVE-2018-0350
8.8HIGH
Summary
A command injection vulnerability in the VPN subsystem configuration of the Cisco SD-WAN Solution allows authenticated remote attackers to inject arbitrary commands executed with root privileges. The issue stems from inadequate input validation, enabling attackers to exploit the affected parameter by authenticating to the device and submitting crafted inputs through a web interface. Successful exploitation can lead to the execution of commands with elevated privileges, posing significant security risks.
Affected Version(s)
Cisco SD-WAN Solution unknown Cisco SD-WAN Solution unknown
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved