CVE-2019-1624
Last modified
CVE-2019-1624 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. EPSS estimates a 4.33% chance of exploitation in the next 30 days.
Description
A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the vManage Web UI. A successful exploit could allow the attacker to execute commands with root privileges.
Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Sd-Wan | < 18.4.0 |
References
- http://www.securityfocus.com/bid/108845Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108845Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1624?
How severe is CVE-2019-1624?
How do I fix CVE-2019-1624?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16234drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux…4.7
- CVE-2019-16235Dino before 2019-09-10 does not properly check the source of…7.5
- CVE-2019-16236Dino before 2019-09-10 does not check roster push authorizat…7.5
- CVE-2019-16237Dino before 2019-09-10 does not properly check the source of…7.5
- CVE-2019-16238Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be…6.1
- CVE-2019-16239process_http_response in OpenConnect before 8.05 has a Buffe…9.8
- CVE-2019-16240A Buffer Overflow and Information Disclosure issue exists in…9.1
- CVE-2019-16241On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authenti…6.8
- CVE-2019-16242On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an …6.8
- CVE-2019-16243On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an …6.1
- CVE-2019-16244OMERO.server before 5.6.1 allows attackers to bypass the sec…9.8
- CVE-2019-16245OMERO before 5.6.1 makes the details of each user available …5.3
Are you affected by CVE-2019-1624?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
