CVE-2019-1624: Cisco SD-WAN Solution Command Injection Vulnerability
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the vManage Web UI. A successful exploit could allow the attacker to execute commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco SD-WAN vulnerability?
The vulnerability ID for this Cisco SD-WAN vulnerability is CVE-2019-1624.
What is the severity rating of CVE-2019-1624?
The severity rating of CVE-2019-1624 is critical with a score of 8.8.
What is the affected software for CVE-2019-1624?
The affected software for CVE-2019-1624 is Cisco SD-WAN up to version 18.4.0.
What is the CWE classification for CVE-2019-1624?
The CWE classification for CVE-2019-1624 is CWE-20 and CWE-77.
How can an attacker exploit CVE-2019-1624?
An authenticated, remote attacker could exploit CVE-2019-1624 by injecting arbitrary commands that are executed with root privileges.