CVE-2020-27129
MEDIUMCisco SD-WAN vManage Software - Command Injection
Title source: llmDescription
A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges. The vulnerability is due to improper validation of commands to the remote management CLI of the affected application. An attacker could exploit this vulnerability by sending malicious requests to the affected application. A successful exploit could allow the attacker to inject arbitrary commands and potentially gain elevated privileges.
Scores
CVSS v3
6.7
EPSS
0.0017
EPSS Percentile
37.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (1)
cisco/sd-wan_vmanage
< 20.3.1
Timeline
Published
Nov 06, 2020
Tracked Since
Feb 18, 2026