Cisco fixes critical vulnerabilities in its SD-WAN, DNA Center solutions
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1624 | A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands tha A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the vManage Web UI. A successful exploit could allow the attacker to execute commands with root privileges. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2019-1626 +1 in the same advisory: …1625 | A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on a A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could exploit this vulnerability by logging in to the vManage Web UI and sending crafted HTTP requests to vManage. A successful exploit could allow attackers to gain elevated privileges and make changes to the configuration that they would not normally be authorized to make. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2019-1843 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco R A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to reload the device and causing a DoS condition. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2019-1848 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critica A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access. NVD description · AI analysis pending | 9.3 | <1% |
| — |
Full article293 words · extracted from helpnetsecurity.com · click to collapse
Cisco has released another batch of fixes for many of its products, including its SD-WAN and DNA Center solutions, its Email Security Appliance, Security Manager, SOHO routers/firewalls, and more.

Critical flaws
CVE-2019-1625 could allow an authenticated, local attacker to elevate lower-level privileges to the root user on a device running a vulnerable version of the Cisco SD-WAN Solution.
Cisco SD-WAN on a number of Cisco’s vEdge routers, its vBond Orchestrator Software, its vSmart Controller Software, and other products. No workarounds are available to mitigate the risk, so users are advised to upgrade to v18.4.1 of the software, which will also fix:
- Another (remotely exploitable) privilege escalation vulnerability (CVE-2019-1626) and
- A command injection flaw (CVE-2019-1624).
CVE-2019-1848 affects Cisco Digital Network Architecture (DNA) Center, a dedicated physical appliance for managing and controlling enterprise networks based on the Cisco DNA.
The vulnerability could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. It affects Cisco DNA Center Software releases prior to 1.3.
None of these flaws is known to be exploited in the wild.
Less urgent fixes
Owners of Cisco’s wireless VPN firewall and routers (RV110W, RV130W, and RV215W) for homes and small offices are also urged to update to close a high-risk DoS vulnerability in the devices’ web-based management interface (CVE-2019-1843) and three additional flaws of medium severity.
These three devices are often targeted by attackers, but luckily this time, the flaws are not that serviceable to most attackers and no PoC exploit code is available.
Most of the other vulnerabilities fixed in this batch od updates are medium risk, so users can take their time implementing them.
Owners and administrators of Cisco equipment and solutions can peruse the companies latest security advisories here.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/06/20/cisco-sd-wan-dna-center-vulnerabilities/