PT-2018-2352 · Cisco · Cisco Wide Area Application Services

Published

2018-06-06

·

Updated

2019-10-09

·

CVE-2018-0352

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Wide Area Application Services Software (affected versions not specified)
Description The issue is related to errors in script file validation in the disk-check.sh and harcap.sh scripts of the Cisco Wide Area Application Services Software. This could allow an authenticated, local attacker with valid user credentials and super user privileges to elevate their privilege level to root and gain full control of the device. The vulnerability is due to insufficient validation of script files executed by the Disk Check Tool. An attacker could exploit this by replacing a script file with a malicious one while the tool is running.
Recommendations For Cisco Wide Area Application Services Software, consider restricting access to the Disk Check Tool until a fix is available. As a temporary workaround, avoid using the Disk Check Tool to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00535
CVE-2018-0352

Affected Products

Cisco Wide Area Application Services