cisco-sa-sd-wan-rhpbE34A: Cisco IOS XE SD-WAN Software Command Injection Vulnerability
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-rhpbE34A
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-sd-wan-rhpbE34A?
The vulnerability cisco-sa-sd-wan-rhpbE34A is considered to have a high severity rating due to its potential for allowing unauthorized command execution.
How do I fix cisco-sa-sd-wan-rhpbE34A?
To fix cisco-sa-sd-wan-rhpbE34A, you should upgrade your Cisco IOS XE Universal Software to a version that is not vulnerable, such as 17.6.1 or later.
Who is affected by cisco-sa-sd-wan-rhpbE34A?
cisco-sa-sd-wan-rhpbE34A affects users of specific versions of Cisco IOS XE Universal Software, including versions 17.6, 17.5.1a, 17.4.2, 17.3.4, and 17.2.3.
What type of attacker could exploit cisco-sa-sd-wan-rhpbE34A?
An authenticated, local attacker could exploit the cisco-sa-sd-wan-rhpbE34A vulnerability to execute arbitrary commands with root privileges.
What causes the cisco-sa-sd-wan-rhpbE34A vulnerability?
The cisco-sa-sd-wan-rhpbE34A vulnerability is caused by insufficient input validation by the system Command Line Interface (CLI).