QID 317193
Date Published: 2022-06-13
QID 317193: Cisco Internetwork Operating System (IOS) XE SD-WAN Software Command Injection Vulnerability (cisco-sa-xesdwcinj-t68PPW7m)
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system.
Affected Products:
Universal Cisco IOS XE Software releases 17.3.1 and later (but earlier than the first fixed release) if they were running in Controller mode.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to execute commands with root privileges.
Customers are advised to refer to cisco-sa-xesdwcinj-t68PPW7m for more information.
- cisco-sa-xesdwcinj-t68PPW7m -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xesdwcinj-t68PPW7m
CVEs related to QID 317193
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-xesdwcinj-t68PPW7m |
|