PT-2017-17261 · Cisco · Cisco Staros
Publicado
2017-07-06
·
Atualizado
2017-07-08
·
CVE-2017-6707
CVSS v3.1
8.2
Alta
| Vetor | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco StarOS versions 11.0 through 21.0
Description
A issue in the CLI command-parsing code of the Cisco StarOS operating system could allow an authenticated, local attacker to execute arbitrary shell commands as a Linux root user on the system. This is because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this by submitting a crafted CLI command for execution in a Linux shell command as a root user.
Recommendations
For Cisco StarOS versions 11.0 through 21.0, update the system to a version that includes the fix for Cisco Bug IDs: CSCvc69329, CSCvc72930.
As a temporary workaround, consider restricting access to the CLI command-parsing code to minimize the risk of exploitation.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Staros