QID 316911

Date Published: 2021-03-30

QID 316911: Cisco IOS XE Software Web UI OS Command Injection Vulnerability(cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9)

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

Successful exploitation could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9 for more information.

    CVEs related to QID 316911

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9