CVE Vulnerabilities

CVE-2020-3388

Improper Authentication

Published: Jul 16, 2020 | Modified: May 23, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI. The attacker must be authenticated to access the CLI. A successful exploit could allow the attacker to execute commands with root privileges.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Sd-wan_firmware Cisco * 18.3.0 (including)
Sd-wan_firmware Cisco 18.4.0 (including) 19.2.2 (excluding)
Sd-wan_firmware Cisco 19.3.0 (including) 20.1.1 (excluding)

Potential Mitigations

References