SB2018011906 - Command execution in Cisco D9800 Network Transport Receiver
Published: January 19, 2018
Security Bulletin ID
SB2018011906
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS command injection (CVE-ID: CVE-2018-0099)
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.The weakness exists in the web management GUI of the Cisco D9800 Network Transport Receiver due to insufficient input validation of GUI command arguments. A remote attacker can inject specially crafted arguments into a vulnerable GUI command and execute commands on the underlying BusyBox operating system with elevated privileges.
Remediation
Install update from vendor's website.