VYPR
Unrated severityNVD Advisory· Published Jan 26, 2020· Updated Nov 15, 2024

Cisco SD-WAN Solution Local Privilege Escalation Vulnerability

CVE-2020-3115

Description

A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system. An exploit could allow the attacker to elevate privileges to root-level privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco SD-WAN vManage CLI input validation flaw lets authenticated local attackers escalate to root.

Vulnerability

A command-line interface (CLI) vulnerability in Cisco SD-WAN Solution vManage software, prior to the fixed releases noted in the advisory, allows authenticated local attackers to elevate privileges to root. The issue is due to insufficient input validation when processing a crafted file. Affected versions include vManage releases before 19.2.2, 19.3.1, and 19.4.1 [1].

Exploitation

An attacker must have local CLI access to the vManage system with a valid, authenticated account. The exploit involves sending a specially crafted file to the affected system. The crafted file is processed by the CLI, bypassing proper validation and leading to privilege escalation [1].

Impact

A successful exploit allows the attacker to elevate privileges from the authenticated user level to root-level privileges on the underlying operating system. This gives the attacker full control over the vManage system, including the ability to modify configuration, access sensitive data, and potentially disrupt network operations [1].

Mitigation

Cisco has released software updates to address this vulnerability. Fixed versions are 19.2.2, 19.3.1, 19.4.1, and later. Customers should upgrade to these or subsequent releases. No workarounds are available. The advisory also includes instructions for customers without service contracts to obtain the updates [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.