Lucene search

K
cvelistCiscoCVELIST:CVE-2018-0432
HistoryOct 05, 2018 - 2:00 p.m.

CVE-2018-0432 Cisco SD-WAN Solution Privilege Escalation Vulnerability

2018-10-0514:00:00
CWE-264
cisco
www.cve.org
9

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

48.3%

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerability by sending a crafted command to the error reporting feature. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.

CNA Affected

[
  {
    "product": "Cisco SD-WAN Solution",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

48.3%

Related for CVELIST:CVE-2018-0432