QID 317036
Date Published: 2021-09-09
QID 317036: Cisco Internetwork Operating System (IOS) XR Software Unauthorized Information Disclosure Vulnerability (cisco-sa-iosxr-infodisc-CjLdGMc5)
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated,
local attacker to view more information than their privileges allow.
Affected Products
Cisco IOS XR Software releases earlier than Release 7.3.2.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to view sensitive configuration information that their privileges might not otherwise allow them to access.
Solution
Customers are advised to refer to cisco-sa-iosxr-infodisc-CjLdGMc5 for more information.
Vendor References
- cisco-sa-iosxr-infodisc-CjLdGMc5 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-infodisc-CjLdGMc5
CVEs related to QID 317036
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxr-infodisc-CjLdGMc5 |
|