Vulnerabilities > Cisco > Vsmart Controller

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-1528 Unspecified vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system.
local
low complexity
cisco
7.8
2020-07-16 CVE-2020-3379 Improper Input Validation vulnerability in Cisco products
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system.
local
low complexity
cisco CWE-20
7.8
2020-07-16 CVE-2020-3351 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6
2019-01-24 CVE-2019-1651 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Vsmart Controller
A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user.
network
low complexity
cisco CWE-119
8.8
2019-01-24 CVE-2019-1650 OS Command Injection vulnerability in Cisco products
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
8.8
2019-01-24 CVE-2019-1648 Improper Input Validation vulnerability in Cisco products
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device.
local
low complexity
cisco CWE-20
7.8
2019-01-24 CVE-2019-1647 Improper Access Control vulnerability in Cisco Sd-Wan and Vsmart Controller
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers.
low complexity
cisco CWE-284
8.0
2019-01-24 CVE-2019-1646 Command Injection vulnerability in Cisco products
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files.
local
low complexity
cisco CWE-77
7.8
2018-10-05 CVE-2018-0433 OS Command Injection vulnerability in Cisco products
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
7.8
2018-07-18 CVE-2018-0351 Command Injection vulnerability in Cisco products
A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-77
7.8