CVE-2017-6718
published 2017-07-04CVE-2017-6718: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information…
PriorityP428medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.1th percentile
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v223-xc7w-3v7p: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level
ghsa_unreviewed·2022-05-17
CVE-2017-6718 [HIGH] CWE-20 GHSA-v223-xc7w-3v7p: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.
Cisco
Cisco IOS XR Software Privilege Escalation Vulnerability
vendor_cisco·2017-06-21·CVSS 6.7
CVE-2017-6718 [MEDIUM] CWE-20 Cisco IOS XR Software Privilege Escalation Vulnerability
Cisco IOS XR Software Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level.
The vulnerability is due to incorrect permission settings on binary files in the affected software. An attacker could exploit this vulnerability by sending crafted commands to the affected device. An exploit could allow the attacker to overwrite binaries on the filesystem and elevate privileges to root.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios1
Cisco
Cisco IOS XR Software Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6718 Cisco IOS XR Software Privilege Escalation Vulnerability
CVE-2017-6718: Cisco IOS XR Software Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. The vulnerability is due to incorrect permission settings on binary files in the affected software. An attacker could exploit this vulnerability by sending crafted commands to the affected device. An exploit could allow the attacker to overwrite binaries on the filesystem and elevate privileges to root . There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvb99384
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99226http://www.securitytracker.com/id/1038741https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios1http://www.securityfocus.com/bid/99226http://www.securitytracker.com/id/1038741https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios1
2017-07-04
Published