CVE-2016-6428
published 2016-10-06CVE-2016-6428: Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.6th percentile
Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x6j2-9h84-jgxx: Cisco IOS XR 6
ghsa_unreviewed·2022-05-17
CVE-2016-6428 [HIGH] GHSA-x6j2-9h84-jgxx: Cisco IOS XR 6
Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.
Cisco
Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
vendor_cisco·2016-10-05·CVSS 6.8
CVE-2016-6428 [MEDIUM] CWE-264 Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of IOS-XR series software could allow an authenticated, local attacker to execute arbitrary code on a targeted system at the root privilege level.
The vulnerability is due to incorrect permissions given to a set of users. An attacker could exploit this vulnerability by authenticating to the device and sending crafted user input to execute commands on the underlying operating system. The user has to be logged-in to the device with valid admin credentials.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.
Cisco
Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-6428 Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
CVE-2016-6428: Cisco IOS XR Software Command-Line Interface Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of IOS-XR series software could allow an authenticated, local attacker to execute arbitrary code on a targeted system at the root privilege level. The vulnerability is due to incorrect permissions given to a set of users. An attacker could exploit this vulnerability by authenticating to the device and sending crafted user input to execute commands on the underlying operating system. The user has to be logged-in to the device with valid admin credentials. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCva38349
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-iosxrhttp://www.securityfocus.com/bid/93416http://www.securitytracker.com/id/1036956http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-iosxrhttp://www.securityfocus.com/bid/93416http://www.securitytracker.com/id/1036956
2016-10-06
Published