CVE-2018-0433 is a command injection vulnerability in the Cisco SD-WAN Solution's command-line interface (CLI). An authenticated, local attacker can exploit insufficient input validation to inject arbitrary commands, which are then executed with root privileges. This vulnerability carries a high CVSS score of 7.8, indicating a significant impact with high confidentiality, integrity, and availability concerns. While no public exploit code is available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, though it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:* | ||
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:vbond_orchestrator:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.