Government of the Republic of Trinidad and Tobago
gov.tt

TTCSIRT-297.032020: TT-CSIRT ADVISORY- CISCO SD-WAN SOLUTION COMMAND INJECTION VULNERABILITY

TTCSIRT-297.032020: TT-CSIRT ADVISORY- CISCO SD-WAN SOLUTION COMMAND INJECTION VULNERABILITY

A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.

The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utility. The attacker must be authenticated to access the CLI utility.

A successful exploit could allow the attacker to execute commands with root privileges

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

The Trinidad and Tobago Cyber Security Incident Response Team (CSIRT) encourages users and administrators to review and apply the necessary updates.

For further review please see the following link: