Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.106282
Kategorie:CISCO
Titel:Cisco IOS Software iox Command Injection Vulnerability
Zusammenfassung:A vulnerability exists in the iox command in Cisco IOS Software that;could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating;system (GOS).
Beschreibung:Summary:
A vulnerability exists in the iox command in Cisco IOS Software that
could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating
system (GOS).

Vulnerability Insight:
This vulnerability is due to insufficient input validation of iox command
line arguments. An attacker could exploit this vulnerability by providing crafted options to the iox command.

Vulnerability Impact:
An exploit could allow the attacker to execute commands of their choice in
the Linux GOS.

Solution:
Upgrade to version 15.6(3.0q)M or later.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-6414
BugTraq ID: 93091
http://www.securityfocus.com/bid/93091
Cisco Security Advisory: 20160921 Cisco IOS and IOS XE iox Command Injection Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-iox
http://www.securitytracker.com/id/1036876
CopyrightCopyright (C) 2016 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.