SB2017050510 - Arbitrary code execution in Cisco Aironet



SB2017050510 - Arbitrary code execution in Cisco Aironet

Published: May 5, 2017

Security Bulletin ID SB2017050510
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2017-3873)

The vulnerability allows an adjacent unauthenticated attacker to execute arbitrary code on the target system.

The weakness exists due to insufficient validation of PnP server responses. An ajacent attacker can respond to PnP configuration requests from the affected device, return malicious PnP responses and execute arbitrary code with root privileges.

Successful exploitation of the vulnerability results in arbitrary code execution.

Remediation

Install update from vendor's website.