SB2016100608 - Privilege escalation in Cisco Network Convergence System 5000 Series



SB2016100608 - Privilege escalation in Cisco Network Convergence System 5000 Series

Published: October 6, 2016 Updated: April 5, 2018

Security Bulletin ID SB2016100608
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2016-6428)

The vulnerability allows a local authenticated user to obtain root privileges on the target system.
The weakness is due to user permissions flaw that lets a malicious user to gain elevated privileges and cause arbitrary command execution with root privileges.
Successful exploitations of the vulnerability allows a local attacker to gain root privileges and execute arbitrary operating system commands on the vulnerable system.

Remediation

Install update from vendor's website.