PT-2016-6902 · Cisco · Cisco Ios Xr

Publicado

2016-10-05

·

Atualizado

2017-07-30

·

CVE-2016-6428

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR version 6.1.1
Description A vulnerability in the command-line interface (CLI) of IOS-XR series software could allow an authenticated, local attacker to execute arbitrary code on a targeted system at the root privilege level. The issue is due to incorrect permissions given to a set of users. An attacker could exploit this by authenticating to the device and sending crafted user input to execute commands on the underlying operating system, requiring valid admin credentials to be logged-in to the device.
Recommendations For Cisco IOS XR version 6.1.1, update to a version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6428

Produtos afetados

Cisco Ios Xr