// For flags

CVE-2023-20035

Cisco IOS XE SD-WAN Software Command Injection Vulnerability

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or a management shell interface and then submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Note: For additional information about specific impacts, see the Details section of this advisory.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-27 CVE Reserved
  • 2023-03-23 CVE Published
  • 2023-03-24 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-146: Improper Neutralization of Expression/Command Delimiters
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8000v Edge
Search vendor "Cisco" for product "Catalyst 8000v Edge"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1100-4g\/6g Integrated Services Router
Search vendor "Cisco" for product "1100-4g\/6g Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1100-4p Integrated Services Router
Search vendor "Cisco" for product "1100-4p Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1100-8p Integrated Services Router
Search vendor "Cisco" for product "1100-8p Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1100 Integrated Services Router
Search vendor "Cisco" for product "1100 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1101-4p Integrated Services Router
Search vendor "Cisco" for product "1101-4p Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1101 Integrated Services Router
Search vendor "Cisco" for product "1101 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1109-2p Integrated Services Router
Search vendor "Cisco" for product "1109-2p Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1109-4p Integrated Services Router
Search vendor "Cisco" for product "1109-4p Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1109 Integrated Services Router
Search vendor "Cisco" for product "1109 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1120 Integrated Services Router
Search vendor "Cisco" for product "1120 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1131 Integrated Services Router
Search vendor "Cisco" for product "1131 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
1160 Integrated Services Router
Search vendor "Cisco" for product "1160 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4221 Integrated Services Router
Search vendor "Cisco" for product "4221 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4321 Integrated Services Router
Search vendor "Cisco" for product "4321 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4331 Integrated Services Router
Search vendor "Cisco" for product "4331 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4351 Integrated Services Router
Search vendor "Cisco" for product "4351 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4431 Integrated Services Router
Search vendor "Cisco" for product "4431 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4451-x Integrated Services Router
Search vendor "Cisco" for product "4451-x Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4451 Integrated Services Router
Search vendor "Cisco" for product "4451 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
4461 Integrated Services Router
Search vendor "Cisco" for product "4461 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Asr 1001-x
Search vendor "Cisco" for product "Asr 1001-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Asr 1002-hx
Search vendor "Cisco" for product "Asr 1002-hx"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Asr 1006-x
Search vendor "Cisco" for product "Asr 1006-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Asr 1009-x
Search vendor "Cisco" for product "Asr 1009-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8200
Search vendor "Cisco" for product "Catalyst 8200"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8300
Search vendor "Cisco" for product "Catalyst 8300"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8300-1n1s-4t2x
Search vendor "Cisco" for product "Catalyst 8300-1n1s-4t2x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8300-1n1s-6t
Search vendor "Cisco" for product "Catalyst 8300-1n1s-6t"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8300-2n2s-4t2x
Search vendor "Cisco" for product "Catalyst 8300-2n2s-4t2x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8300-2n2s-6t
Search vendor "Cisco" for product "Catalyst 8300-2n2s-6t"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8500
Search vendor "Cisco" for product "Catalyst 8500"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8500-4qc
Search vendor "Cisco" for product "Catalyst 8500-4qc"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8500l
Search vendor "Cisco" for product "Catalyst 8500l"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8510csr
Search vendor "Cisco" for product "Catalyst 8510csr"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8510msr
Search vendor "Cisco" for product "Catalyst 8510msr"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8540csr
Search vendor "Cisco" for product "Catalyst 8540csr"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Catalyst 8540msr
Search vendor "Cisco" for product "Catalyst 8540msr"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe Sd-wan
Search vendor "Cisco" for product "Ios Xe Sd-wan"
--
Affected
in Cisco
Search vendor "Cisco"
Csr 1000v
Search vendor "Cisco" for product "Csr 1000v"
--
Safe