Remote Command Injection Vulnerability in Cisco SD-WAN Solution
CVE-2018-0350

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
18 July 2018

Summary

A command injection vulnerability in the VPN subsystem configuration of the Cisco SD-WAN Solution allows authenticated remote attackers to inject arbitrary commands executed with root privileges. The issue stems from inadequate input validation, enabling attackers to exploit the affected parameter by authenticating to the device and submitting crafted inputs through a web interface. Successful exploitation can lead to the execution of commands with elevated privileges, posing significant security risks.

Affected Version(s)

Cisco SD-WAN Solution unknown Cisco SD-WAN Solution unknown

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.