cisco-sa-vepegr-4xynYLUj: Cisco SD-WAN Software Privilege Escalation Vulnerability
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system. The vulnerability is due to incorrect permissions being set when the affected command is executed. An attacker could exploit this vulnerability by executing the affected command on an affected system. A successful exploit could allow the attacker to gain root privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vepegr-4xynYLUj
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-vepegr-4xynYLUj?
The cisco-sa-vepegr-4xynYLUj vulnerability has a high severity level as it allows local attackers to elevate privileges to the root group.
How do I fix cisco-sa-vepegr-4xynYLUj?
To fix the cisco-sa-vepegr-4xynYLUj vulnerability, update Cisco SD-WAN Software to version 20.3.2 or 20.1.2 as specified in the advisory.
Who is affected by cisco-sa-vepegr-4xynYLUj?
The cisco-sa-vepegr-4xynYLUj vulnerability affects users of Cisco SD-WAN Software versions prior to 20.3.2 and 20.1.2.
What causes cisco-sa-vepegr-4xynYLUj?
The cisco-sa-vepegr-4xynYLUj vulnerability is caused by incorrect permissions being set when executing an affected command.
Can external attackers exploit cisco-sa-vepegr-4xynYLUj?
No, cisco-sa-vepegr-4xynYLUj can only be exploited by authenticated local attackers.