Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
BID:102788
CVE-2018-115 |Info
Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
| Bugtraq ID: | 102788 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-0115 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 17 2018 12:00AM |
| Updated: | Jan 17 2018 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco StarOS 0 Cisco ASR 5000 Series 21.5 Cisco ASR 5000 Series 21.4 Cisco ASR 5000 Series 21.3.5 Cisco ASR 5000 Series 21.3.0.67664 |
| Not Vulnerable: | |
Discussion
Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
Cisco StarOS for ASR 5000 Series Routers is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and execute arbitrary commands with root privileges.
This issue is being tracked by Cisco bug ID CSCvf93332.
Cisco StarOS for ASR 5000 Series Routers is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and execute arbitrary commands with root privileges.
This issue is being tracked by Cisco bug ID CSCvf93332.
Exploit / POC
Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco StarOS for ASR 5000 Series Routers CVE-2018-0115 Local Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco StarOS CLI Command Injection Vulnerability (Cisco)