9
CVSSv2

CVE-2018-0432

Published: 05/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote malicious user to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerability by sending a crafted command to the error reporting feature. A successful exploit could allow the malicious user to gain root-level privileges and take full control of the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco vedge_100_firmware

cisco vedge_1000_firmware

cisco vedge_2000_firmware

cisco vedge_5000_firmware

cisco vmanage network management system -

Vendor Advisories

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration An attacker could exploit this vuln ...