Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1651

Опубликовано: 24 янв. 2019
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:vsmart_controller:-:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01554
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119
CWE-119

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

CVSS3: 9.9
fstec
около 7 лет назад

Уязвимость компонента vContainer программно-определяемой сети Cisco SD-WAN, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код с привилегиями root

EPSS

Процентиль: 81%
0.01554
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119
CWE-119