CVE-2020-3595: Cisco SD-WAN Software Privilege Escalation Vulnerability
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is due to incorrect permissions being set when the affected command is executed. An attacker could exploit this vulnerability by executing the affected command on an affected system. A successful exploit could allow the attacker to gain root privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco SD-WAN Software vulnerability?
The vulnerability ID of this Cisco SD-WAN Software vulnerability is CVE-2020-3595.
How severe is CVE-2020-3595?
CVE-2020-3595 has a severity score of 7.8 out of 10, which is considered high.
How does this vulnerability allow privilege escalation?
This vulnerability allows an authenticated, local attacker to elevate privileges to the root group on the underlying operating system due to incorrect permissions being set when the affected command is executed.
Which versions of Cisco SD-WAN Software are affected by CVE-2020-3595?
CVE-2020-3595 affects Cisco SD-WAN Software versions 20.1.2 up to exclusive and versions 20.3 up to exclusive (up to version 20.3.2).
Is there a fix available for CVE-2020-3595?
Yes, Cisco has released a security advisory with patches and mitigations for CVE-2020-3595. Please refer to the following link for more information: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vepegr-4xynYLUj)