Lucene search

K
ciscoCiscoCISCO-SA-IOSXE-ARBFILE-FUXSKKDE
HistoryMar 24, 2021 - 4:00 p.m.

Cisco IOS XE SD-WAN Software Arbitrary File Corruption Vulnerability

2021-03-2416:00:00
tools.cisco.com
57
cisco
ios xe
sd-wan
vulnerability
cli
local attacker
file overwrite
software updates
insufficient validation.

EPSS

0

Percentile

5.1%

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system.

This vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of any arbitrary file that resides on the underlying host file system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-arbfile-FUxskKDE [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-arbfile-FUxskKDE”]

Affected configurations

Vulners
Node
ciscocisco_ios_xe_softwareMatch16.11
OR
ciscocisco_ios_xe_softwareMatch16.12
OR
ciscocisco_ios_xe_softwareMatch17.2
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoios_xe_sd-wanMatchany
OR
ciscocisco_ios_xe_softwareMatch16.11.1
OR
ciscocisco_ios_xe_softwareMatch16.11.1a
OR
ciscocisco_ios_xe_softwareMatch16.11.1b
OR
ciscocisco_ios_xe_softwareMatch16.11.2
OR
ciscocisco_ios_xe_softwareMatch16.11.1s
OR
ciscocisco_ios_xe_softwareMatch16.11.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1
OR
ciscocisco_ios_xe_softwareMatch16.12.1s
OR
ciscocisco_ios_xe_softwareMatch16.12.1a
OR
ciscocisco_ios_xe_softwareMatch16.12.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1w
OR
ciscocisco_ios_xe_softwareMatch16.12.2
OR
ciscocisco_ios_xe_softwareMatch16.12.1y
OR
ciscocisco_ios_xe_softwareMatch16.12.2a
OR
ciscocisco_ios_xe_softwareMatch16.12.3
OR
ciscocisco_ios_xe_softwareMatch16.12.2s
OR
ciscocisco_ios_xe_softwareMatch16.12.1x
OR
ciscocisco_ios_xe_softwareMatch16.12.1t
OR
ciscocisco_ios_xe_softwareMatch16.12.2t
OR
ciscocisco_ios_xe_softwareMatch16.12.3s
OR
ciscocisco_ios_xe_softwareMatch16.12.1z
OR
ciscocisco_ios_xe_softwareMatch16.12.3a
OR
ciscocisco_ios_xe_softwareMatch16.12.1z2
OR
ciscocisco_ios_xe_softwareMatch17.2.1
OR
ciscocisco_ios_xe_softwareMatch17.2.1r
OR
ciscocisco_ios_xe_softwareMatch17.2.1a
OR
ciscocisco_ios_xe_softwareMatch17.2.1v
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoios_xe_sd-wanMatchany
VendorProductVersionCPE
ciscocisco_ios_xe_software16.11cpe:2.3:a:cisco:cisco_ios_xe_software:16.11:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.12cpe:2.3:a:cisco:cisco_ios_xe_software:16.12:*:*:*:*:*:*:*
ciscocisco_ios_xe_software17.2cpe:2.3:a:cisco:cisco_ios_xe_software:17.2:*:*:*:*:*:*:*
ciscocisco_ios_xe_softwareanycpe:2.3:a:cisco:cisco_ios_xe_software:any:*:*:*:*:*:*:*
ciscoios_xe_sd-wananycpe:2.3:o:cisco:ios_xe_sd-wan:any:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1cpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1acpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1a:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1bcpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1b:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.2cpe:2.3:a:cisco:cisco_ios_xe_software:16.11.2:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.11.1scpe:2.3:a:cisco:cisco_ios_xe_software:16.11.1s:*:*:*:*:*:*:*
Rows per page:
1-10 of 321

EPSS

0

Percentile

5.1%

Related for CISCO-SA-IOSXE-ARBFILE-FUXSKKDE