A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerability by sending a crafted command to the error reporting feature. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2018-10-05T14:00:00Z
Updated: 2024-09-16T19:31:53.140Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0432
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-10-05T14:29:01.497
Modified: 2019-10-09T23:32:04.130
Link: CVE-2018-0432
Redhat
No data.