CVE-2019-12629
Cisco SD-WAN vManage Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vulnerability by configuring a malicious username on the login page of the affected solution. A successful exploit could allow the attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system.
Una vulnerabilidad en la WebUI del Cisco SD-WAN Solution, podría permitir a un atacante remoto autenticado inyectar y ejecutar comandos arbitrarios con privilegios de usuario vmanage en un sistema afectado. La vulnerabilidad es debido a una comprobación de entrada insuficiente de los parámetros de datos para determinados campos en la solución afectada. Un atacante podría explotar esta vulnerabilidad mediante la configuración de un nombre de usuario malicioso en la página de inicio de sesión de la solución afectada. Una explotación con éxito podría permitir al atacante inyectar y ejecutar comandos arbitrarios con privilegios de usuario vmanage en un sistema afectado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-06-04 CVE Reserved
- 2020-01-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-100 Search vendor "Cisco" for product "Vedge-100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-1000 Search vendor "Cisco" for product "Vedge-1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-100b Search vendor "Cisco" for product "Vedge-100b" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-2000 Search vendor "Cisco" for product "Vedge-2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-5000 Search vendor "Cisco" for product "Vedge-5000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100m Search vendor "Cisco" for product "Vedge 100m" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | < 18.3.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " < 18.3.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100wm Search vendor "Cisco" for product "Vedge 100wm" | - | - |
Safe
|