CVE-2018-0433: Cisco SD-WAN Solution Command Injection Vulnerability
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utility. The attacker must be authenticated to access the CLI utility. A successful exploit could allow the attacker to execute commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0433?
CVE-2018-0433 is a vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution that could allow an authenticated, local attacker to inject arbitrary commands with root privileges.
What is the severity of CVE-2018-0433?
The severity of CVE-2018-0433 is rated as high.
How does CVE-2018-0433 affect Cisco products?
CVE-2018-0433 affects Cisco SD-WAN Solution, specifically vEdge and vManage platforms.
How can an attacker exploit CVE-2018-0433?
An attacker can exploit CVE-2018-0433 by injecting arbitrary commands into the command-line interface (CLI) with root privileges.
How can I fix CVE-2018-0433?
To fix CVE-2018-0433, update the affected Cisco SD-WAN Solution to version 18.3.0 or later. Refer to the Cisco Security Advisory for more information.