Cisco Security Advisory - Cisco IOx for IOS XE Software Command Injection Vulnerability

Started by Netwörkheäd, April 03, 2021, 06:27:07 PM

Previous topic - Next topic

Netwörkheäd

Cisco IOx for IOS XE Software Command Injection Vulnerability

A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user.


This vulnerability is due to incomplete validation of fields in the application packages loaded onto IOx. An attacker could exploit this vulnerability by creating a crafted application .tar file and loading it onto the device. A successful exploit could allow the attacker to perform command injection into the underlying operating system as the root user.


Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-cmdinj-RkSURGHG



     
         
Security Impact Rating:  Medium
   
   
       
CVE: CVE-2021-1384
Source: Cisco IOx for IOS XE Software Command Injection Vulnerability
Let's not argue. Let's network!