A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system. An exploit could allow the attacker to elevate privileges to root-level privileges.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-sdwan-priv-esc | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-01-25 21:15
Updated : 2020-01-31 09:06
NVD link : CVE-2020-3115
Mitre link : CVE-2020-3115
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
cisco
- sd-wan_firmware
- vedge-1000
- vedge_100m
- vedge_100wm
- vedge-100
- vedge-5000
- vedge-2000
- vedge-100b