PT-2017-17193 · Cisco · Cisco Policy Suite
Published
2017-05-18
·
Updated
2019-10-09
·
CVE-2017-6623
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Policy Suite (CPS) Software versions 10.0.0, 10.1.0, 11.0.0
Description
A vulnerability in a script file installed as part of the Cisco Policy Suite (CPS) Software distribution could allow an authenticated, local attacker to escalate their privilege level to root. This is due to incorrect sudoers permissions on the script file. An attacker could exploit this by authenticating to the device, providing crafted user input at the CLI, and using the script file to escalate their privilege level and execute commands as root. A successful exploit could allow the attacker to acquire root-level privileges and take full control of the appliance. The attacker must be logged-in to the device with valid credentials for a specific set of users.
Recommendations
For Cisco Policy Suite (CPS) Software versions 10.0.0, 10.1.0, or 11.0.0, consider restricting access to the vulnerable script file until a patch is available.
As a temporary workaround, consider disabling the script file to prevent privilege escalation until a fix is applied.
Restrict access to the CLI for users who do not need it to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Policy Suite