Risk | Low |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2018-0217 CVE-2018-0224 |
CWE-ID | CWE-77 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Cisco ASR 5000 Series Hardware solutions / Firmware |
Vendor | Cisco Systems, Inc |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU10899
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2018-0217
CWE-ID:
CWE-77 - Command injection
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers due to insufficient validation of commands that are supplied to certain configurations in the CLI. A local attacker can inject specially crafted arguments into a vulnerable CLI command, insert and execute arbitrary commands in the CLI.
Update to version 21.7.M0.68711, 21.7.D0.68717, 21.7.0.68846, 21.7.0.
Cisco ASR 5000 Series: 21.3.0.67664 - 21.7.0
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-staros
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU10900
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2018-0224
CWE-ID:
CWE-77 - Command injection
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers due toinsufficient validation of user-supplied input. A local attacker can inject malicious arguments into a vulnerable CLI command and execute arbitrary commands with root privileges.
Update to version 21.6.RU0.68455, 21.6.D0.68319, 21.6.A0.68321, 21.5.M0.68317, 21.5.C0.68318, 21.5.0.68363, 21.5.0
Cisco ASR 5000 Series: 21.3.0.67664 - 21.5.0
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-staros1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.