Lucene search

K
ciscoCiscoCISCO-SA-20170705-USF3
HistoryJul 05, 2017 - 4:00 p.m.

Cisco Ultra Services Framework Staging Server Arbitrary Command Execution Vulnerability

2017-07-0516:00:00
tools.cisco.com
20

EPSS

0.003

Percentile

68.5%

A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user.

The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command inputs to execute Linux shell commands as the root user. An exploit could allow the attacker to execute arbitrary shell commands as the Linux root user.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-usf3 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-usf3”]

Affected configurations

Vulners
Node
ciscoultra_services_framework_staging_serverMatchany
OR
ciscoultra_services_framework_staging_serverMatchany
VendorProductVersionCPE
ciscoultra_services_framework_staging_serveranycpe:2.3:a:cisco:ultra_services_framework_staging_server:any:*:*:*:*:*:*:*

EPSS

0.003

Percentile

68.5%

Related for CISCO-SA-20170705-USF3