Impact
A flaw in Cisco ThousandEyes Virtual Appliance’s web‑based management interface permits an authenticated, remote attacker to inject arbitrary operating system commands. The vulnerability stems from improper validation of user‑supplied input, allowing the attacker to save configuration data containing malicious payloads. Executing the payload grants the attacker root‑level privileges on the appliance. This issue is classified as a command‑injection weakness (CWE‑78).
Affected Systems
The affected product is Cisco ThousandEyes Enterprise Agent. No specific version information is cited, so all deployed instances of the appliance are potentially vulnerable unless patched or otherwise secured.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. An attacker must possess valid administrative credentials and be able to access the web interface; from that position, they can execute arbitrary commands with root privileges. The risk is therefore confined to environments where the management interface is reachable and administrative accounts are compromised or weak.
OpenCVE Enrichment