CVE-2023-20035
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or a management shell interface and then submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Note: For additional information about specific impacts, see the Details section of this advisory.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-10-27 CVE Reserved
- 2023-03-23 CVE Published
- 2023-03-24 EPSS Updated
- 2024-10-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-146: Improper Neutralization of Expression/Command Delimiters
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8000v Edge Search vendor "Cisco" for product "Catalyst 8000v Edge" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g\/6g Integrated Services Router Search vendor "Cisco" for product "1100-4g\/6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4p Integrated Services Router Search vendor "Cisco" for product "1100-4p Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-8p Integrated Services Router Search vendor "Cisco" for product "1100-8p Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100 Integrated Services Router Search vendor "Cisco" for product "1100 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101-4p Integrated Services Router Search vendor "Cisco" for product "1101-4p Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101 Integrated Services Router Search vendor "Cisco" for product "1101 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109-2p Integrated Services Router Search vendor "Cisco" for product "1109-2p Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109-4p Integrated Services Router Search vendor "Cisco" for product "1109-4p Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109 Integrated Services Router Search vendor "Cisco" for product "1109 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1120 Integrated Services Router Search vendor "Cisco" for product "1120 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1131 Integrated Services Router Search vendor "Cisco" for product "1131 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1160 Integrated Services Router Search vendor "Cisco" for product "1160 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4221 Integrated Services Router Search vendor "Cisco" for product "4221 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4321 Integrated Services Router Search vendor "Cisco" for product "4321 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331 Integrated Services Router Search vendor "Cisco" for product "4331 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4351 Integrated Services Router Search vendor "Cisco" for product "4351 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4431 Integrated Services Router Search vendor "Cisco" for product "4431 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4451-x Integrated Services Router Search vendor "Cisco" for product "4451-x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4451 Integrated Services Router Search vendor "Cisco" for product "4451 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4461 Integrated Services Router Search vendor "Cisco" for product "4461 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1001-x Search vendor "Cisco" for product "Asr 1001-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1002-hx Search vendor "Cisco" for product "Asr 1002-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1006-x Search vendor "Cisco" for product "Asr 1006-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1009-x Search vendor "Cisco" for product "Asr 1009-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8200 Search vendor "Cisco" for product "Catalyst 8200" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8300 Search vendor "Cisco" for product "Catalyst 8300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8300-1n1s-4t2x Search vendor "Cisco" for product "Catalyst 8300-1n1s-4t2x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8300-1n1s-6t Search vendor "Cisco" for product "Catalyst 8300-1n1s-6t" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8300-2n2s-4t2x Search vendor "Cisco" for product "Catalyst 8300-2n2s-4t2x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8300-2n2s-6t Search vendor "Cisco" for product "Catalyst 8300-2n2s-6t" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8500 Search vendor "Cisco" for product "Catalyst 8500" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8500-4qc Search vendor "Cisco" for product "Catalyst 8500-4qc" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8500l Search vendor "Cisco" for product "Catalyst 8500l" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8510csr Search vendor "Cisco" for product "Catalyst 8510csr" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8510msr Search vendor "Cisco" for product "Catalyst 8510msr" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8540csr Search vendor "Cisco" for product "Catalyst 8540csr" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Catalyst 8540msr Search vendor "Cisco" for product "Catalyst 8540msr" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Sd-wan Search vendor "Cisco" for product "Ios Xe Sd-wan" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Csr 1000v Search vendor "Cisco" for product "Csr 1000v" | - | - |
Safe
|