QID 317146
Date Published: 2022-04-19
QID 317146: Cisco SD-WAN vManage Software Privilege Escalation Vulnerability (cisco-sa-sdwan-privesc-vman-tEJFpBSL)
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to exploit this vulnerability.
Affected Products
Cisco SD-WAN 18.3 and earlier
Cisco SD-WAN 18.4
Cisco SD-WAN 19.2
Cisco SD-WAN 20.1
Cisco SD-WAN 20.3
Cisco SD-WAN 20.4
Cisco SD-WAN 20.5
Cisco SD-WAN 20.6
Cisco SD-WAN 20.7
QID detection logic:
The QID checks for Cisco SD WAN version retrieved via Unix Auth using "show system status" command
A successful exploit could allow the attacker to escalate their privileges on the affected system from a low-privileged user to the root user.
Customers are advised to refer to cisco-sa-sdwan-privesc-vman-tEJFpBSL for more information.
- cisco-sa-sdwan-privesc-vman-tEJFpBSL -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-vman-tEJFpBSL
CVEs related to QID 317146
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sdwan-privesc-vman-tEJFpBSL |
|