ZeroHour

CVE-2019-1648

CVSS 3.1
7.8 high
EPSS
<1%p30
Published
()
Modified
Description

A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a crafted file to the directory where the user group configuration is located in the underlying operating system. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.

Vendors
cisco
Products
vedge 100 firmware, vedge 1000 firmware, vedge 2000 firmware, vedge 5000 firmware, sd-wan, vbond orchestrator, vmanage network management, vsmart controller
Weakness
CWE-264, CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news