Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
BID:100376
CVE-2017-6773 |Info
Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
| Bugtraq ID: | 100376 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-6773 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 16 2017 12:00AM |
| Updated: | Aug 16 2017 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco StarOS 0 Cisco ASR 5000 Series 21.0.v0.65839 |
| Not Vulnerable: | |
Discussion
Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
Cisco StarOS for ASR 5000 Series Routers is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and execute arbitrary commands with system privileges.
This issue is being tracked by Cisco bug ID CSCvd47722.
Cisco StarOS for ASR 5000 Series Routers is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and execute arbitrary commands with system privileges.
This issue is being tracked by Cisco bug ID CSCvd47722.
Exploit / POC
Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco StarOS for ASR 5000 Series Routers CVE-2017-6773 Local Command Injection Vulnerability
References:
References: