PT-2017-17261 · Cisco · Cisco Staros
Published
2017-07-06
·
Updated
2017-07-08
·
CVE-2017-6707
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco StarOS versions 11.0 through 21.0
Description
A issue in the CLI command-parsing code of the Cisco StarOS operating system could allow an authenticated, local attacker to execute arbitrary shell commands as a Linux root user on the system. This is because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this by submitting a crafted CLI command for execution in a Linux shell command as a root user.
Recommendations
For Cisco StarOS versions 11.0 through 21.0, update the system to a version that includes the fix for Cisco Bug IDs: CSCvc69329, CSCvc72930.
As a temporary workaround, consider restricting access to the CLI command-parsing code to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Staros