CVE-2018-0432: Cisco SD-WAN Solution Privilege Escalation Vulnerability
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerability by sending a crafted command to the error reporting feature. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0432?
CVE-2018-0432 is a vulnerability in the error reporting feature of the Cisco SD-WAN Solution that could allow an authenticated, remote attacker to gain elevated privileges on an affected device.
What is the severity of CVE-2018-0432?
CVE-2018-0432 has a severity rating of 8.8, which is classified as critical.
Which software is affected by CVE-2018-0432?
CVE-2018-0432 affects the Cisco Vedge 100, Cisco Vedge 1000, Cisco Vedge 2000, and Cisco Vedge 5000 firmware versions up to and excluding 18.3.0.
How can an attacker exploit CVE-2018-0432?
An attacker can exploit CVE-2018-0432 by exploiting a failure to properly validate certain parameters in the error reporting application of the Cisco SD-WAN Solution.
How can I fix CVE-2018-0432?
To fix CVE-2018-0432, it is recommended to upgrade to a version of the Cisco SD-WAN Solution that includes a fix for this vulnerability.