A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or a management shell interface and then submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Note: For additional information about specific impacts, see the Details section of this advisory.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1100-4g\/6g Integrated Services Router
Subscribe
1100-4p Integrated Services Router
Subscribe
1100-8p Integrated Services Router
Subscribe
1100 Integrated Services Router
Subscribe
1101-4p Integrated Services Router
Subscribe
1101 Integrated Services Router
Subscribe
1109-2p Integrated Services Router
Subscribe
1109-4p Integrated Services Router
Subscribe
1109 Integrated Services Router
Subscribe
1120 Integrated Services Router
Subscribe
1131 Integrated Services Router
Subscribe
1160 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451-x Integrated Services Router
Subscribe
4451 Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
Asr 1001-x
Subscribe
Asr 1002-hx
Subscribe
Asr 1006-x
Subscribe
Asr 1009-x
Subscribe
Catalyst 8000v Edge
Subscribe
Catalyst 8200
Subscribe
Catalyst 8300
Subscribe
Catalyst 8300-1n1s-4t2x
Subscribe
Catalyst 8300-1n1s-6t
Subscribe
Catalyst 8300-2n2s-4t2x
Subscribe
Catalyst 8300-2n2s-6t
Subscribe
Catalyst 8500
Subscribe
Catalyst 8500-4qc
Subscribe
Catalyst 8500l
Subscribe
Catalyst 8510csr
Subscribe
Catalyst 8510msr
Subscribe
Catalyst 8540csr
Subscribe
Catalyst 8540msr
Subscribe
Csr 1000v
Subscribe
Ios Xe Sd-wan
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24214 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or a management shell interface and then submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Note: For additional information about specific impacts, see the Details section of this advisory. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-10-28T16:32:57.941Z
Reserved: 2022-10-27T00:00:00
Link: CVE-2023-20035
Updated: 2024-08-02T08:57:35.562Z
Status : Modified
Published: 2023-03-23T17:15:14.030
Modified: 2024-11-21T07:40:24.403
Link: CVE-2023-20035
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD