QID 316915
Date Published: 2021-04-08
QID 316915: Cisco IOS and IOS XE Software Privilege Escalation Vulnerability(cisco-sa-XE-FSM-Yj8qJbJc)
A vulnerability in the dragonite debugger of Cisco IOS Software and Cisco IOS XE Software
could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege.
Affected Products
Cisco devices if they were running a vulnerable release of Cisco IOS or IOS XE Software.
Catalyst IE3200 Rugged Series Switches
Catalyst IE3300 Rugged Series Switches
Catalyst IE3400 Rugged Series Switches
Catalyst IE3400 Heavy Duty Series Switches
Embedded Services 3300 Series Switches (ESS 3300)
Note: Potential detection, as device is not confirmed.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege.
Customers are advised to refer to cisco-sa-XE-FSM-Yj8qJbJc for more information.
- cisco-sa-XE-FSM-Yj8qJbJc -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-FSM-Yj8qJbJc
CVEs related to QID 316915
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-XE-FSM-Yj8qJbJc |
|