CVE-2019-16103: Critical severity silver-peak unity edgeconnect sd-wan firmware vulnerability
Published Sep 8, 2019
·Updated
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
Affected Software
2 affected components
Silver-peak Unity Edgeconnect Sd-wan Firmware=8.1.4.9_65644
Silver-peak Unity Edgeconnect Sd-wan
Event History
Sep 8, 2019
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Silver Peak EdgeConnect SD-WAN vulnerability?
The vulnerability ID for this Silver Peak EdgeConnect SD-WAN vulnerability is CVE-2019-16103.
2
What is the severity of CVE-2019-16103?
The severity of CVE-2019-16103 is critical with a severity value of 7.2.
3
How does CVE-2019-16103 allow privilege escalation?
CVE-2019-16103 allows privilege escalation for administrators from the menu to a root Bash OS shell via the spsshell feature.
4
Which version of Silver Peak EdgeConnect SD-WAN firmware is affected by CVE-2019-16103?
The version 8.1.4.9_65644 of Silver Peak EdgeConnect SD-WAN firmware is affected by CVE-2019-16103.
5
Is Silver Peak Unity Edgeconnect SD-WAN vulnerable to CVE-2019-16103?
No, Silver Peak Unity Edgeconnect SD-WAN is not vulnerable to CVE-2019-16103.