CVE-2014-7990
published 2014-11-07CVE-2014-7990: Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows…
PriorityP420medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.34%
26.9th percentile
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.5e | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Challenge/Response Bypass Vulnerability
vendor_cisco·2014-11-06·CVSS 6.8
CVE-2014-7990 [MEDIUM] CWE-20 Cisco IOS XE Software Challenge/Response Bypass Vulnerability
Cisco IOS XE Software Challenge/Response Bypass Vulnerability
A vulnerability in the request system shell command supported by specific Cisco IOS XE platforms (WS-C3850, WS-C3650, AIR-CT5760, and WS-C4500X) could allow an authenticated, local attacker with administrative privilege (15) to access the underlying Linux root shell.
The vulnerability is due to improper parsing of the challenge response. An attacker could exploit this vulnerability by entering a crafted challenge response. An exploit could allow the attacker to compromise the system. The request system shell command is available only if the service internal command is configured, which is not recommended.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this
GHSA
GHSA-m25p-g3cf-hvcp: Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2014-7990 [MEDIUM] CWE-20 GHSA-m25p-g3cf-hvcp: Cisco IOS XE 3
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990http://tools.cisco.com/security/center/viewAlert.x?alertId=36351http://www.securityfocus.com/bid/70968http://www.securitytracker.com/id/1031179https://exchange.xforce.ibmcloud.com/vulnerabilities/98529http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990http://tools.cisco.com/security/center/viewAlert.x?alertId=36351http://www.securityfocus.com/bid/70968http://www.securitytracker.com/id/1031179https://exchange.xforce.ibmcloud.com/vulnerabilities/98529
2014-11-07
Published