PT-2017-17279 · Cisco · Cisco Ios Xr

Publicado

2017-07-05

·

Atualizado

2019-10-03

·

CVE-2017-6728

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software version 6.2.1.BASE
Description A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of incorrect permissions given to a set of users. An attacker could exploit this vulnerability by logging in to an affected device and elevating their privileges via crafted input. A successful exploit could allow the attacker to gain root-level privileges and take full control of the affected device.
Recommendations For Cisco IOS XR Software version 6.2.1.BASE, update to a fixed release such as 6.3.1.15i.BASE, 6.2.3.1i.BASE, or 6.2.2.15i.BASE to resolve the issue.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6728

Produtos afetados

Cisco Ios Xr