QID 316906
Date Published: 2021-03-26
QID 316906: Cisco IOS XE Software Fast Reload Vulnerabilities(cisco-sa-fast-Zqr6DD5)
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850,
Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated,
local attacker to either execute arbitrary code on the underlying operating system,
install and boot a malicious software image, or execute unsigned binaries on an affected device.
Affected Products
Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches
if they are running a vulnerable release of Cisco IOS XE Software.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to either execute arbitrary code on the underlying operating system
or execute unsigned code and bypass the image verification check part of the secure boot process.
Customers are advised to refer to cisco-sa-fast-Zqr6DD5 for more information.
- cisco-sa-fast-Zqr6DD5 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fast-Zqr6DD5
CVEs related to QID 316906
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-fast-Zqr6DD5 |
|