PT-2019-2436 · Cisco · Cisco Sd-Wan Solution

Published

2019-06-19

·

Updated

2021-08-12

·

CVE-2019-1625

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN Solution (affected versions not specified)
Description The issue is related to insufficient authorization enforcement in the command-line interface of the Cisco SD-WAN Solution, allowing an authenticated, local attacker to elevate lower-level privileges to the root user. This could enable the attacker to make configuration changes to the system as the root user by executing specific commands after authenticating to the targeted device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02214
CVE-2019-1625

Affected Products

Cisco Sd-Wan Solution