QID 316911
Date Published: 2021-03-30
QID 316911: Cisco IOS XE Software Web UI OS Command Injection Vulnerability(cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9)
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
Successful exploitation could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device.
Solution
Customers are advised to refer to cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9 for more information.
Vendor References
- cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9
CVEs related to QID 316911
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ios-xe-os-cmd-inj-Ef6TV5e9 |
|