cisco-sa-sdwclici-cvrQpH9v: Cisco SD-WAN Solution Command Injection Vulnerability
A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utility. The attacker must be authenticated to access the CLI utility. A successful exploit could allow the attacker to execute commands with root privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwclici-cvrQpH9v
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-sdwclici-cvrQpH9v?
The cisco-sa-sdwclici-cvrQpH9v vulnerability is considered critical due to potential exploitation allowing command injection with root privileges.
How do I fix cisco-sa-sdwclici-cvrQpH9v?
To address cisco-sa-sdwclici-cvrQpH9v, apply the latest patches provided by Cisco for the SD-WAN Solution software.
Who is affected by cisco-sa-sdwclici-cvrQpH9v?
The cisco-sa-sdwclici-cvrQpH9v vulnerability affects users of the Cisco SD-WAN Solution software that have not implemented the necessary security measures.
What type of attack can be executed using cisco-sa-sdwclici-cvrQpH9v?
An attacker exploiting the cisco-sa-sdwclici-cvrQpH9v vulnerability can perform arbitrary command injection with elevated privileges.
Is user authentication required to exploit cisco-sa-sdwclici-cvrQpH9v?
Yes, exploitation of the cisco-sa-sdwclici-cvrQpH9v vulnerability requires authentication by a local user.