PT-2018-8779 · Cisco+1 · Vbond Orchestrator+9
Publicado
2018-07-18
·
Atualizado
2019-10-09
·
CVE-2018-0351
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco SD-WAN Solution versions prior to 18.3.0
vBond Orchestrator Software versions prior to 18.3.0
vEdge 100 Series Routers versions prior to 18.3.0
vEdge 1000 Series Routers versions prior to 18.3.0
vEdge 2000 Series Routers versions prior to 18.3.0
vEdge 5000 Series Routers versions prior to 18.3.0
vEdge Cloud Router Platform versions prior to 18.3.0
vManage Network Management Software versions prior to 18.3.0
vSmart Controller Software versions prior to 18.3.0
Description
A vulnerability in the command-line tcpdump utility could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges due to insufficient input validation. The attacker must be authenticated to access the tcpdump utility and could exploit this by submitting crafted input. A successful exploit could allow the attacker to execute commands with root privileges.
Recommendations
For Cisco SD-WAN Solution version prior to 18.3.0, update to Release 18.3.0 or later.
For vBond Orchestrator Software version prior to 18.3.0, update to Release 18.3.0 or later.
For vEdge 100 Series Routers version prior to 18.3.0, update to Release 18.3.0 or later.
For vEdge 1000 Series Routers version prior to 18.3.0, update to Release 18.3.0 or later.
For vEdge 2000 Series Routers version prior to 18.3.0, update to Release 18.3.0 or later.
For vEdge 5000 Series Routers version prior to 18.3.0, update to Release 18.3.0 or later.
For vEdge Cloud Router Platform version prior to 18.3.0, update to Release 18.3.0 or later.
For vManage Network Management Software version prior to 18.3.0, update to Release 18.3.0 or later.
For vSmart Controller Software version prior to 18.3.0, update to Release 18.3.0 or later.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Sd-Wan Solution
Tcpdump
Vbond Orchestrator
Vedge 100 Series Routers
Vedge 1000 Series Routers
Vedge 2000 Series Routers
Vedge 5000 Series Routers
Vedge Cloud Router Platform
Vmanage Network Management
Vsmart Controller