Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106894
Category:CISCO
Title:Cisco IOS XR Software Privilege Escalation Vulnerability (cisco-sa-20170621-ios1)
Summary:A vulnerability in the CLI of Cisco IOS XR Software could allow; an authenticated, local attacker to elevate privileges to the root level.
Description:Summary:
A vulnerability in the CLI of Cisco IOS XR Software could allow
an authenticated, local attacker to elevate privileges to the root level.

Vulnerability Insight:
The vulnerability is due to incorrect permission settings on
binary files in the affected software. An attacker could exploit this vulnerability by sending
crafted commands to the affected device.

Vulnerability Impact:
An exploit could allow the attacker to overwrite binaries on the
filesystem and elevate privileges to root.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6718
BugTraq ID: 99226
http://www.securityfocus.com/bid/99226
http://www.securitytracker.com/id/1038741
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.