QID 317354

Date Published: 2023-09-20

QID 317354: Cisco Internetwork Operating System (IOS) XR Software Image Verification Vulnerability (cisco-sa-lnt-L9zOkBz5)

A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.

Affected Products
Cisco IOS XR 7.5.2 prior to 7.6 Cisco IOS XR 7.7 prior to 7.10.1

QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to execute arbitrary code on an affected device.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to cisco-sa-lnt-L9zOkBz5 for more information.

    CVEs related to QID 317354

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-lnt-L9zOkBz5 URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-L9zOkBz5