QID 316925
Date Published: 2021-04-15
QID 316925: Cisco IOS XR Software Command Injection Vulnerability(cisco-sa-xr-cmdinj-vsKGherc)
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated,
local attacker to inject arbitrary commands that are executed
with root privileges on the underlying Linux operating system (OS) of an affected device.
Affected Products
Cisco IOS XR Software releases earlier than Release 7.3.1.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to execute commands on the underlying Linux OS with root privileges.
Customers are advised to refer to cisco-sa-xr-cmdinj-vsKGherc for more information.
- cisco-sa-xr-cmdinj-vsKGherc -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr-cmdinj-vsKGherc
CVEs related to QID 316925
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-xr-cmdinj-vsKGherc |
|