VYPR
Unrated severityNVD Advisory· Published Sep 8, 2019· Updated Aug 5, 2024

CVE-2019-16103

CVE-2019-16103

Description

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows administrators to escalate privileges from the management menu to a root OS shell via the spsshell feature.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows administrators to escalate privileges from the management menu to a root OS shell via the spsshell feature.

Vulnerability

CVE-2019-16103 affects Silver Peak EdgeConnect SD-WAN versions prior to 8.1.7.x. The vulnerability resides in the spsshell feature, which is accessible from the management menu. It allows authenticated administrators to escape the restricted menu environment and gain access to a full root Bash shell on the underlying operating system [1].

Exploitation

An attacker must first possess administrative credentials for the EdgeConnect SD-WAN appliance. With those privileges, the attacker can navigate to the spsshell option from the management menu. By selecting this feature, the administrator is presented with a root shell prompt, effectively bypassing the intended command restrictions [1]. No additional network position, user interaction, or race condition is required beyond administrative login.

Impact

Successful exploitation grants the attacker a root shell on the EdgeConnect device. This provides complete control over the operating system, including the ability to read or modify any file, install persistent malware, alter network configuration, and disrupt SD-WAN operations. The compromise is at the highest privilege level (root) and affects the entire appliance [1].

Mitigation

Silver Peak released a fix in version 8.1.7.x. Administrators should upgrade all affected EdgeConnect SD-WAN appliances to version 8.1.7.x or later immediately. No workaround is available for unpatched versions. The issue is not known to be listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.