CVE-2020-3388

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI. The attacker must be authenticated to access the CLI. A successful exploit could allow the attacker to execute commands with root privileges.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sd-wan_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:1100-4g_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltegb_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltena_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-6g_integrated_services_router:-:*:*:*:*:*:*:*

History

23 May 2023, 13:55

Type Values Removed Values Added
CPE cpe:2.3:h:cisco:isr1100-4gltena:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:isr1100-6g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:isr1100-4gltegb:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:isr1100-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-6g_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4g_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltegb_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:1100-4gltena_integrated_services_router:-:*:*:*:*:*:*:*
First Time Cisco 1100-4gltegb Integrated Services Router
Cisco 1100-4g Integrated Services Router
Cisco 1100-6g Integrated Services Router
Cisco 1100-4gltena Integrated Services Router

Information

Published : 2020-07-16 18:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-3388

Mitre link : CVE-2020-3388

CVE.ORG link : CVE-2020-3388


JSON object : View

Products Affected

cisco

  • sd-wan_firmware
  • 1100-4gltena_integrated_services_router
  • 1100-4g_integrated_services_router
  • 1100-4gltegb_integrated_services_router
  • 1100-6g_integrated_services_router
CWE
CWE-287

Improper Authentication