PT-2017-2891 · Cisco · Cisco Ios Xe+1
Publicado
2017-03-09
·
Atualizado
2019-10-09
·
CVE-2017-6796
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers (affected versions not specified)
Description
A vulnerability exists in the USB-modem code due to improper input validation of the
platform usb modem command in the CLI. This could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device by modifying the platform usb modem command. A successful exploit could allow the attacker to inject and execute arbitrary commands on the underlying operating system.Recommendations
For Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers, consider disabling the
platform usb modem command in the CLI as a temporary workaround until a patch is available. Restrict access to the CLI to minimize the risk of exploitation. Avoid using the platform usb modem command until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Asr 920 Series Aggregation Services Routers
Cisco Ios Xe