peter bassill · operator
$ cve CVE-2019-1651 JSON

CVE-2019-1651

9.9
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)

In your normal cycle

Critical by CVSS (9.9), but no sign of active exploitation.

Description

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the vContainer. An attacker could exploit this vulnerability by sending a malicious file to an affected vContainer instance. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected vContainer, which could result in a DoS condition that the attacker could use to execute arbitrary code as the root user.

Scoring

CVSS9.9 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS4.85% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2019-01-24
Last modified2026-06-17

Affected (1)

VendorProduct
ciscovsmart controller

References

→ the Explorer  ·  watch your stack  ·  NVD