Cisco IOS and IOS XE Software CVE-2018-0123 Local Arbitrary File Overwrite Vulnerability
BID:102967
CVE-2018-123 |Info
Cisco IOS and IOS XE Software CVE-2018-0123 Local Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 102967 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-0123 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2018 12:00AM |
| Updated: | Feb 07 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Cisco IOS XE Software 0 Cisco Ios 16.7.1 |
| Not Vulnerable: | |
Discussion
Cisco IOS and IOS XE Software CVE-2018-0123 Local Arbitrary File Overwrite Vulnerability
Cisco IOS and IOS XE Software are prone to local arbitrary file-overwrite vulnerability because it fails to properly validate certain diagnostic shell commands.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application.
This issue is being tracked by Cisco Bug ID CSCvg41950.
Cisco IOS and IOS XE Software are prone to local arbitrary file-overwrite vulnerability because it fails to properly validate certain diagnostic shell commands.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application.
This issue is being tracked by Cisco Bug ID CSCvg41950.
Solution / Fix
Cisco IOS and IOS XE Software CVE-2018-0123 Local Arbitrary File Overwrite Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.