QID 317236
Date Published: 2022-10-18
QID 317236: Cisco Internetwork Operating System (IOS) XE Software for Catalyst 9200 Series Switches Arbitrary Code Execution Vulnerability (cisco-sa-ios-xe-cat-verify-D4NEQA6q)
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time.
Affected Products:
This vulnerability affects Cisco Catalyst 9200 Series Switches if they are running a vulnerable release of Cisco IOS XE Software.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to boot a malicious software image or execute unsigned code and bypass the image verification check part of the boot process of the affected device.
Customers are advised to refer to cisco-sa-ios-xe-cat-verify-D4NEQA6q for more information.
- cisco-sa-ios-xe-cat-verify-D4NEQA6q -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-cat-verify-D4NEQA6q
CVEs related to QID 317236
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ios-xe-cat-verify-D4NEQA6q |
|