CVE-2019-12629 describes a command injection vulnerability in the WebUI of Cisco SD-WAN Solution products, including various vEdge models. An authenticated, remote attacker can exploit insufficient input validation by configuring a malicious username on the login page. This allows for the execution of arbitrary commands with vmanage user privileges, leading to a high severity CVSS score of 7.2. Despite its high severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.