CVE-2018-0432: Cisco Vedge 1000 Firmware

High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error reporting application configuration. An attacker could exploit this vulnerability by sending a crafted command to the error reporting feature. A successful exploit could allow the attacker to gain root-level privileges and take full control of the device.

Affected products

  • Cisco Vedge 1000 Firmware: before 18.3.0 (fixed in 18.3.0)
  • Cisco Vedge 100 Firmware: before 18.3.0 (fixed in 18.3.0)
  • Cisco Vedge 2000 Firmware: before 18.3.0 (fixed in 18.3.0)
  • Cisco Vedge 5000 Firmware: before 18.3.0 (fixed in 18.3.0)
  • Cisco Vmanage Network Management System: affected versions not specified

Published 2018-10-05. Last modified 2026-06-17.