Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rwj-5cr9-523w

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

EPSS

Процентиль: 81%
0.01554
Низкий

8.8 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.9
nvd
около 7 лет назад

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

CVSS3: 9.9
fstec
около 7 лет назад

Уязвимость компонента vContainer программно-определяемой сети Cisco SD-WAN, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код с привилегиями root

EPSS

Процентиль: 81%
0.01554
Низкий

8.8 High

CVSS3

Дефекты

CWE-119