Rewterz
Rewterz Threat Alert – Oski Data Stealer Malware – Active IOCs
June 3, 2021
Rewterz
Rewterz Threat Alert – Unknown Threat Actors Targeting different Pakistani Sectors – Active IOCs
June 3, 2021

Rewterz Threat Advisory – CVE-2021-1528 – Cisco SD-WAN Software Privilege Escalation Vulnerability

Severity

High

Analysis Summary

CVE-2021-1528

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system.An attacker could exploit this vulnerability by invoking a privileged process in the affected system. A successful exploit could allow the attacker to perform actions with the privileges of the root user.

Impact

  • Privilege Escalation

Affected Vendors

Cisco

Affected Products

  • Cisco SD-WAN vBond Orchestrator Software
  • Cisco SD-WAN vEdge Cloud Routers
  • Cisco SD-WAN vEdge Routers
  • Cisco SD-WAN vManage Software
  • Cisco SD-WAN vSmart Controller Software

Remediation

Refer to Cisco advisory for the complete list of affected product and their respective patches

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-fuErCWwF