Privilege escalation in Cisco IOS XR - CVE-2017-6718

 

Privilege escalation in Cisco IOS XR - CVE-2017-6718

Published: June 22, 2017


Vulnerability identifier: #VU7178
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6718
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated attacker to gain elevated privileges on the target system.

The vulnerability exists in the CLI of Cisco IOS XR Software due to incorrect permission settings on binary files. A local attacker can send specially crafted commands to the affected device, overwrite binaries on the filesystem and gain root privileges.

Successful exploitation of the vulnerability results in privileges escalation.


Affected software

Cisco IOS XR

How to mitigate CVE-2017-6718

Install update from vendor's website.


External References

Related Security Bulletins