QID 317144
Date Published: 2022-04-19
QID 317144: Cisco Internetwork Operating System (IOS) XE Software for Cisco Catalyst 9000 Family Switches and Catalyst 9000 Family Wireless Controllers Privilege Escalation Vulnerability (cisco-sa-ewlc-priv-esc-ybvHKO5)
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and
Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device.
Affected Products
Cisco products if they are running a vulnerable release of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches
or Cisco Catalyst 9000 Family Wireless Controllers:
Catalyst 9300 Series Switches
Catalyst 9400 Series Switches
Catalyst 9500 Series Switches
Catalyst 9800 Embedded Wireless Controllers for Catalyst 9300, 9400, and 9500 Series Switches
Catalyst 9800 Series Wireless Controllers
Catalyst 9800-CL Wireless Controllers for Cloud
Embedded Wireless Controllers on Catalyst Access Points
Note: No support for Catalyst 9800-CL Wireless Controllers for Cloud
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE SDWAN version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to execute arbitrary commands with level 15 privileges on the affected device.
Customers are advised to refer to cisco-sa-ewlc-priv-esc-ybvHKO5 for more information.
- cisco-sa-ewlc-priv-esc-ybvHKO5 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-priv-esc-ybvHKO5
CVEs related to QID 317144
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ewlc-priv-esc-ybvHKO5 |
|