Command injection in Cisco IOS XR - CVE-2017-6719

 

Command injection in Cisco IOS XR - CVE-2017-6719

Published: June 22, 2017


Vulnerability identifier: #VU7177
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6719
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated attacker to execute arbitrary commands on the host operating system.

The vulnerability exists in the CLI of Cisco IOS XR Software due to insufficient input validation. A local attacker can send a specially crafted input to a command in a specific group and execute arbitrary commands with root privileges.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Cisco IOS XR

How to mitigate CVE-2017-6719

Install update from vendor's website.


External References

Related Security Bulletins