CVE-2016-1456
published 2016-07-15CVE-2016-1456: The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.5th percentile
The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container access, aka Bug ID CSCuz62721.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Command Injection Vulnerability
vendor_cisco·2016-07-14·CVSS 6.8
CVE-2016-1456 [MEDIUM] CWE-78 Cisco IOS XR Software Command Injection Vulnerability
Cisco IOS XR Software Command Injection Vulnerability
A vulnerability in the command-line utility of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with elevated privileges.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting crafted input to a command in a specific container. A successful exploit could allow the attacker to execute arbitrary commands on the affected system with root privileges.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAd
Cisco
Cisco IOS XR Software Command Injection Vulnerability
vendor_cisco
CVE-2016-1456 Cisco IOS XR Software Command Injection Vulnerability
CVE-2016-1456: Cisco IOS XR Software Command Injection Vulnerability
A vulnerability in the command-line utility of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with elevated privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting crafted input to a command in a specific container. A successful exploit could allow the attacker to execute arbitrary commands on the affected system with root privileges. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-78, CWE-78
Bug IDs: CSCuz62721
GHSA
GHSA-4q37-wpfr-m8xh: The CLI in Cisco IOS XR 6
ghsa_unreviewed·2022-05-17
CVE-2016-1456 [HIGH] GHSA-4q37-wpfr-m8xh: The CLI in Cisco IOS XR 6
The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container access, aka Bug ID CSCuz62721.
No detection rules found.
No public exploits indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160714-ios-xrhttp://www.securityfocus.com/bid/91785http://www.securitytracker.com/id/1036311http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160714-ios-xrhttp://www.securityfocus.com/bid/91785http://www.securitytracker.com/id/1036311
2016-07-15
Published