CVE-2019-1650 is a high-severity vulnerability in Cisco SD-WAN Solution that allows an authenticated, remote attacker to overwrite arbitrary files and escalate privileges to root. This is due to improper input validation in the CLI's save command. With a CVSS score of 8.8, exploitation is straightforward, requiring only authenticated access to the network. There is currently no public exploit code available, and the vulnerability has received minimal community discussion or media coverage, indicating a low active exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:* | ||
< 18.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.