QID 316919
Date Published: 2021-04-20
QID 316919: Cisco IOx Application Environment Path Traversal Vulnerability(cisco-sa-iox-pt-hWGcPf7g)
A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms
could allow an authenticated, remote attacker to conduct directory traversal
attacks and read and write files on the underlying operating system or host system.
Affected Products
Cisco products if they were running a vulnerable software release and
configured with the Cisco IOx application hosting environment for following products:
809 Industrial Integrated Services Routers (ISRs) : From 15.8(3)M2 prior to 15.9(3)M4
829 Industrial ISRs IOS Software : From 15.8(3)M2 and later
Devices running Cisco IOS XE Software : From 16.11.1 and later prior to 17.3.2, From 17.4.0 prior to 17.4.2,From 17.5.0 prior to 17.5.1
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system.
Customers are advised to refer to cisco-sa-iox-pt-hWGcPf7g for more information.
- cisco-sa-iox-pt-hWGcPf7g -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-pt-hWGcPf7g
CVEs related to QID 316919
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iox-pt-hWGcPf7g |
|