Total vulnerabilities in the database
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a crafted file to the directory where the user group configuration is located in the underlying operating system. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.
Software | From | Fixed in |
---|---|---|
cisco / vedge_100_firmware | - | - |
cisco / vedge_1000_firmware | - | - |
cisco / vedge_2000_firmware | - | - |
cisco / vedge_5000_firmware | - | - |
cisco / sd-wan | - | 18.4.0 |