CVE-2016-6414
published 2016-09-22CVE-2016-6414: iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.5th percentile
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_ios_xe_iox | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and IOS XE iox Command Injection Vulnerability
vendor_cisco·2016-09-21·CVSS 6.8
CVE-2016-6414 [MEDIUM] CWE-78 Cisco IOS and IOS XE iox Command Injection Vulnerability
Cisco IOS and IOS XE iox Command Injection Vulnerability
A vulnerability exists in the iox command in Cisco IOS and IOS XE Software that could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating system (GOS).
This vulnerability is due to insufficient input validation of iox command line arguments. An attacker could exploit this vulnerability by providing crafted options to the iox command. An exploit could allow the attacker to execute commands of their choice in the Linux GOS.
Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso
Cisco
Cisco IOS and IOS XE iox Command Injection Vulnerability
vendor_cisco
CVE-2016-6414 Cisco IOS and IOS XE iox Command Injection Vulnerability
CVE-2016-6414: Cisco IOS and IOS XE iox Command Injection Vulnerability
A vulnerability exists in the iox command in Cisco IOS and IOS XE Software that could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating system (GOS). This vulnerability is due to insufficient input validation of iox command line arguments. An attacker could exploit this vulnerability by providing crafted options to the iox command. An exploit could allow the attacker to execute commands of their choice in the Linux GOS. Cisco has not released software updates that address this vulnerability.
CWE: CWE-78, CWE-78
Bug IDs: CSCuz59223
GHSA
GHSA-j6mp-pxmq-5rv6: iox in Cisco IOS, possibly 15
ghsa_unreviewed·2022-05-17
CVE-2016-6414 [HIGH] CWE-78 GHSA-j6mp-pxmq-5rv6: iox in Cisco IOS, possibly 15
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-ioxhttp://www.securityfocus.com/bid/93091http://www.securitytracker.com/id/1036876http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-ioxhttp://www.securityfocus.com/bid/93091http://www.securitytracker.com/id/1036876
2016-09-22
Published