QID 317041
Date Published: 2021-09-20
QID 317041: Cisco Internetwork Operating System (IOS) XR Software for Network Convergence System 540 Series Routers Image Verification Vulnerabilities (cisco-sa-lnt-QN9mCzwn)
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers,
only when running Cisco IOS XR NCS540L software images, could allow an authenticated, local attacker
to execute arbitrary code on the underlying operating system.
Affected Products
Cisco devices if they were running a vulnerable release of Cisco IOS XR Software:
NCS 540 Series Routers that are running the NCS540L images
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to execute arbitrary code on the affected device.
Solution
Customers are advised to refer to cisco-sa-lnt-QN9mCzwn for more information.
Vendor References
- cisco-sa-lnt-QN9mCzwn -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-QN9mCzwn
CVEs related to QID 317041
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-lnt-QN9mCzwn |
|