PT-2018-8776 · Cisco · Vbond Orchestrator+8

Published

2018-07-18

·

Updated

2020-08-31

·

CVE-2018-0348

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN Solution versions prior to 18.3.0 vBond Orchestrator Software versions prior to 18.3.0 vEdge 100 Series Routers versions prior to 18.3.0 vEdge 1000 Series Routers versions prior to 18.3.0 vEdge 2000 Series Routers versions prior to 18.3.0 vEdge 5000 Series Routers versions prior to 18.3.0 vEdge Cloud Router Platform versions prior to 18.3.0 vManage Network Management Software versions prior to 18.3.0 vSmart Controller Software versions prior to 18.3.0
Description A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The issue is due to insufficient input validation. An attacker could exploit this by authenticating to the device and submitting malicious input to the load command within the VPN subsystem. A successful exploit could allow an attacker to execute commands with root privileges.
Recommendations For versions prior to 18.3.0, update to Release 18.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected CLI parameter until a patch is available. Avoid using the load command within the VPN subsystem in the affected CLI until the issue is resolved.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0348

Affected Products

Cisco Sd-Wan Solution
Vbond Orchestrator
Vedge 100 Series Routers
Vedge 1000 Series Routers
Vedge 2000 Series Routers
Vedge 5000 Series Routers
Vedge Cloud Router Platform
Vmanage Network Management
Vsmart Controller