PT-2020-3123 · Cisco · Cisco Sd-Wan Vmanage

Published

2020-07-15

·

Updated

2023-05-23

·

CVE-2020-3388

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage Software (affected versions not specified)
Description The issue is related to insufficient input validation in the CLI of the software, allowing an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this, an attacker must first authenticate to the device and then submit crafted input to the CLI. A successful exploit could allow the attacker to execute commands with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2020-03415
CVE-2020-3388

Affected Products

Cisco Sd-Wan Vmanage