cbcvebase.
CVE-2019-1647
published 2019-01-24

CVE-2019-1647: A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to…

PriorityP345high8CVSS 3.0
AVAACLPRLUINSUCHIHAH
EPSS
0.81%
52.9th percentile
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed services. An exploit could allow the attacker to retrieve and modify critical system files.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_sd-wan_solution
ciscosd-wan< 18.4.018.4.0
ciscosd-wan_solution_unauthorized_access

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.