QID 317144

Date Published: 2022-04-19

QID 317144: Cisco Internetwork Operating System (IOS) XE Software for Cisco Catalyst 9000 Family Switches and Catalyst 9000 Family Wireless Controllers Privilege Escalation Vulnerability (cisco-sa-ewlc-priv-esc-ybvHKO5)

A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and
Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device.
Affected Products
Cisco products if they are running a vulnerable release of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches
or Cisco Catalyst 9000 Family Wireless Controllers:
Catalyst 9300 Series Switches
Catalyst 9400 Series Switches
Catalyst 9500 Series Switches
Catalyst 9800 Embedded Wireless Controllers for Catalyst 9300, 9400, and 9500 Series Switches
Catalyst 9800 Series Wireless Controllers
Catalyst 9800-CL Wireless Controllers for Cloud
Embedded Wireless Controllers on Catalyst Access Points
Note: No support for Catalyst 9800-CL Wireless Controllers for Cloud

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE SDWAN version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to execute arbitrary commands with level 15 privileges on the affected device.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ewlc-priv-esc-ybvHKO5 for more information.

    CVEs related to QID 317144

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ewlc-priv-esc-ybvHKO5 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-priv-esc-ybvHKO5