CVE-2019-1646 describes a privilege escalation vulnerability in the local CLI of Cisco SD-WAN Solution devices. This flaw stems from insufficient sanitization of user input for specific CLI commands, allowing an authenticated, local attacker to craft malicious commands. A successful exploit grants the attacker elevated privileges, enabling them to modify device configurations or further compromise the system. While rated High severity (CVSS 7.8) due to its local attack vector and high impact on confidentiality, integrity, and availability, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:* | ||
< 18.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.