PT-2017-2017 · Cisco · Cisco Ios Xe
Published
2017-03-22
·
Updated
2017-07-12
·
CVE-2017-3858
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software version 16.2.1
Description
A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of HTTP parameters supplied by the user. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the affected web page parameter. A successful exploit could allow the attacker to execute commands with root privileges.
Recommendations
For Cisco IOS XE Software version 16.2.1, update to a newer version that addresses this vulnerability. As a temporary workaround, consider restricting access to the HTTP Server feature to minimize the risk of exploitation. Avoid using the affected web page parameter until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe