QID 316907
Date Published: 2021-03-30
QID 316907: Cisco IOS XE Software Arbitrary Code Execution Vulnerability(cisco-sa-XE-ACE-75K3bRWe)
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device.
Solution
Customers are advised to refer to cisco-sa-XE-ACE-75K3bRWe for more information.
Vendor References
- cisco-sa-XE-ACE-75K3bRWe -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-ACE-75K3bRWe
CVEs related to QID 316907
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-XE-ACE-75K3bRWe |
|