CVE-2018-0432 describes a privilege escalation vulnerability in the error reporting feature of Cisco SD-WAN Solution, affecting various vEdge devices and vManage. An authenticated, remote attacker can exploit improper parameter validation by sending a crafted command, leading to root-level privileges and full device control. This high-severity vulnerability (CVSS 8.8) has a low attack complexity and no user interaction required. While no public exploit code or active exploitation has been observed, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vmanage_network_management_system:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.