CVE-2020-3379

HIGH

Cisco SD-WAN Solution Software - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain administrative privileges.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 17.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-264
Status published
Products (3)
cisco/sd-wan_firmware < 18.3.0
cisco/vbond_orchestrator
cisco/vsmart_controller
Published Jul 16, 2020
Tracked Since Feb 18, 2026