QID 316903
Date Published: 2021-03-26
QID 316903: Cisco IOS XE Software Easy Virtual Switching System Arbitrary Code Execution Vulnerability(cisco-sa-ios-xe-evss-code-exe-8cw5VSvw)
A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches
and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated,
remote attacker to execute arbitrary code on the
underlying Linux operating system of an affected device.
Affected Products
Cisco Catalyst 4500 and 4500-X Series Switches if they are running a vulnerable release of Cisco IOS XE Software and
one of the following conditions is true:
i. The switch is being converted from standalone mode to virtual switch mode using the Easy VSS feature.
ii. Cisco Discovery Protocol is enabled with Application type, length, value (TLV) information.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to trigger a denial of service (DoS) condition
or execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.
Customers are advised to refer to cisco-sa-ios-xe-evss-code-exe-8cw5VSvw for more information.
- cisco-sa-ios-xe-evss-code-exe-8cw5VSvw -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-evss-code-exe-8cw5VSvw
CVEs related to QID 316903
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ios-xe-evss-code-exe-8cw5VSvw |
|