CVE-2017-6719Improper Input Validation in Cisco IOS XR

Severity
6.7MEDIUMNVD
EPSS
0.2%
top 63.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 4
Latest updateMay 17

Description

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages1 packages

NVDcisco/ios_xr6.0.2, 6.0.2.01+1

🔴Vulnerability Details

2
GHSA
GHSA-ghq9-xp8j-4pwc: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating s2022-05-17
CVEList
CVE-2017-6719: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating s2017-07-04

📋Vendor Advisories

1
Cisco
Cisco IOS XR Software Local Command Injection Vulnerability2017-06-21
CVE-2017-6719 — Improper Input Validation in Cisco | cvebase