5 Bugs in Cisco SD-WAN Allows Attackers to Inject Arbitrary Commands With Root Privileges

Cisco fixed 5 security flaws in Cisco SD-WAN that allow attackers to make unauthorized changes to the system, and to execute the arbitrary commands.

Out of five, three are high severity flaws and the flaws are due to insufficient input validation, now Cisco released a fix for all the flaws.

CVE-2020-3265 – Privilege Escalation

The vulnerability in Cisco SD-WAN Solution software is due to insufficient input validation, it allows a local attacker to escalate the privileges to root on the vulnerable machine.

It affects all the Cisco products running Cisco SD-WAN Solution software release earlier than Release 19.2.2.

CVE-2020-3266 – Command Injection Vulnerability

The vulnerability resides in CLI of Cisco SD-WAN Solution software. it allows a local attacker to inject arbitrary commands with root privileges.

It affects all the Cisco products running Cisco SD-WAN Solution software release earlier than Release 19.2.2.

CVE-2020-3264 – Buffer Overflow Vulnerability

The vulnerability resides in Cisco SD-WAN Solution software allow an authenticated local attacker to cause a buffer overflow on the vulnerable device.

It affects all the Cisco products running Cisco SD-WAN Solution software release earlier than Release 19.2.2.

CVE-2019-16010 – Cross-Site Scripting Vulnerability

The vulnerability resides in the web UI of the Cisco SD-WAN vManage software that allows an authenticated remote attacker to launch a cross-site scripting (XSS) attack.

It affects all the Cisco products running Cisco SD-WAN Solution software release earlier than Release 19.2.2.

CVE-2019-16012 – SQL Injection Vulnerability

The vulnerability resides in the web UI of Cisco SD-WAN Solution that allows an authenticated remote attacker to conduct SQL injection attacks on an affected system.

It affects all the Cisco products running Cisco SD-WAN Solution software release earlier than Release 19.2.2.

Read More:

Cisco Small Business Switches Vulnerabilities allows Attackers to Access Sensitive Information and Cause DoS

Cisco Webex Flaw Let Unauthenticated Remote Attackers to Join Private Meetings Without Password

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hackers Target Mobile Users Using PWA JavaScript to Bypass Browser Security

A sophisticated new injection campaign has been uncovered, targeting mobile users through malicious third-party JavaScript…

9 minutes ago

Docker Zombie Malware Infects Containers for Crypto Mining and Self-Replication

A novel malware campaign targeting containerized infrastructures has emerged, exploiting insecurely exposed Docker APIs to…

16 minutes ago

Hackers Masquerade as Organizations to Steal Payroll Logins and Redirect Payments from Employees

ReliaQuest, hackers have deployed a cunning search engine optimization (SEO) poisoning scheme to orchestrate payroll…

24 minutes ago

PupkinStealer Exploits Web Browser Passwords and App Tokens to Exfiltrate Data Through Telegram

A newly identified .NET-based information-stealing malware, dubbed PupkinStealer (also known as PumpkinStealer in some reports),…

1 hour ago

71 Fake Websites Impersonating German Retailer to Steal Payment Information

Recorded Future Payment Fraud Intelligence has uncovered a sprawling network of 71 fraudulent e-commerce domains…

1 hour ago

New Scan Uncovers 150K Industrial Systems Worldwide Vulnerable to Cyberattacks

A groundbreaking study leveraging advanced application-layer scanning has exposed approximately 150,000 industrial control systems (ICS)…

2 hours ago