← Back

CVE-2019-1626

nvd nist
Published: Jun 20, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could exploit this vulnerability by logging in to the vManage Web UI and sending crafted HTTP requests to vManage. A successful exploit could allow attackers to gain elevated privileges and make changes to the configuration that they would not normally be authorized to make.

Affected (1)

1 product
Sd Wan Firmware
Configuration A
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Up to 18.3.6
Running on/withPlatform Versions
Cisco
Vedge 100
All versions
Cisco
Vedge 1000
All versions
Cisco
Vedge 100b
All versions
Cisco
Vedge 2000
All versions
Cisco
Vedge 5000
All versions
Cisco
Vedge 100m
All versions
Cisco
Vedge 100wm
All versions

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.