VYPR
Unrated severityNVD Advisory· Published Jan 26, 2020· Updated Nov 15, 2024

Cisco SD-WAN vManage Command Injection Vulnerability

CVE-2019-12629

Description

A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vulnerability by configuring a malicious username on the login page of the affected solution. A successful exploit could allow the attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote command injection in Cisco SD-WAN vManage WebUI via malicious username, fixed in 18.3.0.

Vulnerability

The vulnerability exists in the WebUI of Cisco SD-WAN vManage releases earlier than 18.3.0. It is due to insufficient input validation of data parameters for certain fields. An authenticated attacker can inject arbitrary commands by configuring a malicious username on the login page [1].

Exploitation

An attacker needs valid authentication credentials to access the WebUI. The exploit is performed by entering a crafted username string that includes command injection payloads during the login process. No additional user interaction is required beyond the attacker's own actions [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with vmanage user privileges on the affected system. This can lead to full compromise of the SD-WAN management plane, including potential data exfiltration, configuration modification, and further lateral movement [1].

Mitigation

Cisco has released software updates that address this vulnerability. Fixed version is Release 18.3.0 and later. There are no workarounds available. Users should upgrade to a patched release as soon as possible [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.