VYPR
Unrated severityNVD Advisory· Published Jul 18, 2018· Updated Nov 29, 2024

CVE-2018-0345

CVE-2018-0345

Description

A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected software. The vulnerability is due to insufficient validation of command arguments that are passed to the configuration and management database of the affected software. An attacker could exploit this vulnerability by creating custom functions that contain malicious code and are executed as the vmanage user of the configuration management system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected software. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vManage Network Management Software, vSmart Controller Software. Cisco Bug IDs: CSCvi69937.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote code execution via insufficient command validation in Cisco SD-WAN configuration database.

Vulnerability

An authenticated, remote attacker can execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the Cisco SD-WAN Solution. The vulnerability is due to insufficient validation of command arguments passed to the configuration and management database (CSCvi69937). Affected products running a release prior to Release 18.3.0 include: vBond Orchestrator Software, vManage Network Management Software, and vSmart Controller Software [1].

Exploitation

An attacker must have valid authentication credentials for the configuration and management database. The attacker creates custom functions containing malicious code, which are then executed as the vmanage user [1]. No additional user interaction or race condition is required beyond the authenticated session.

Impact

Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the vmanage user within the configuration management system, leading to full compromise of the affected component's administrative capabilities [1].

Mitigation

Cisco has released free software updates; the vulnerability is fixed in Cisco SD-WAN Solution Release 18.3.0 and later [1]. Customers should upgrade to a fixed release and consult the Cisco Security Advisory for additional guidance [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.