CVE-2019-1650
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the save command in the CLI of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system of an affected device and escalate their privileges to the root user.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.48% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-78
- Affected
- cisco/vedge 100 firmware · cisco/vedge 1000 firmware · cisco/vedge 2000 firmware · cisco/vedge 5000 firmware · cisco/sd-wan · cisco/vbond orchestrator · cisco/vmanage network management · cisco/vsmart controller
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/106716Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-file-writeVendor Advisory
- http://www.securityfocus.com/bid/106716Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-file-writeVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.