PT-2017-2891 · Cisco · Cisco Ios Xe+1
Published
2017-03-09
·
Updated
2019-10-09
·
CVE-2017-6796
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers (affected versions not specified)
Description
A vulnerability exists in the USB-modem code due to improper input validation of the
platform usb modem command in the CLI. This could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device by modifying the platform usb modem command. A successful exploit could allow the attacker to inject and execute arbitrary commands on the underlying operating system.Recommendations
For Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers, consider disabling the
platform usb modem command in the CLI as a temporary workaround until a patch is available. Restrict access to the CLI to minimize the risk of exploitation. Avoid using the platform usb modem command until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asr 920 Series Aggregation Services Routers
Cisco Ios Xe