High severity7.8NVD Advisory· Published Jan 24, 2019· Updated Jun 17, 2026
CVE-2019-1648
CVE-2019-1648
Description
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit this vulnerability by writing a crafted file to the directory where the user group configuration is located in the underlying operating system. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:a:cisco:vbond_orchestrator:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:vmanage_network_management:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:vsmart_controller:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:vedge_1000_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:vedge_100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:vedge_2000_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:vedge_5000_firmware:*:*:*:*:*:*:*:*
- Range: n/a
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106719nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-sol-escalnvdVendor Advisory
News mentions
0No linked articles in our index yet.