Lucene search

K
ciscoCiscoCISCO-SA-IOX-8WHGN5DL
HistoryFeb 01, 2023 - 4:00 p.m.

Cisco IOx Application Hosting Environment Command Injection Vulnerability

2023-02-0116:00:00
tools.cisco.com
66
cisco
iox
application hosting
command injection
vulnerability
authentication
remote attacker
arbitrary commands
root access
operating system
sanitization
application deployment
software updates

EPSS

0.003

Percentile

70.0%

A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system.

This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-8whGn5dL [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-8whGn5dL”]

Affected configurations

Vulners
Node
ciscoiosMatch15.6t
OR
ciscoiosMatch15.6m
OR
ciscoiosMatch15.7m
OR
ciscoiosMatch15.8m
OR
ciscoiosMatch15.9m
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch16.3
OR
ciscocisco_ios_xe_softwareMatch16.4
OR
ciscocisco_ios_xe_softwareMatch16.5
OR
ciscocisco_ios_xe_softwareMatch16.6
OR
ciscocisco_ios_xe_softwareMatch16.7
OR
ciscocisco_ios_xe_softwareMatch16.8
OR
ciscocisco_ios_xe_softwareMatch16.9
OR
ciscocisco_ios_xe_softwareMatch16.10
OR
ciscocisco_ios_xe_softwareMatch16.11
OR
ciscocisco_ios_xe_softwareMatch16.12
OR
ciscocisco_ios_xe_softwareMatch17.1
OR
ciscocisco_ios_xe_softwareMatch17.2
OR
ciscocisco_ios_xe_softwareMatch17.3
OR
ciscocisco_ios_xe_softwareMatch17.4
OR
ciscocisco_ios_xe_softwareMatch17.5
OR
ciscocisco_ios_xe_softwareMatch17.6
OR
ciscocisco_ios_xe_softwareMatch17.7
OR
ciscocisco_ios_xe_softwareMatch17.8
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoic3000_industrial_compute_gatewayMatchany
OR
ciscoir510_operating_systemMatchany
OR
ciscocgr1000_compute_moduleMatchany
OR
ciscoiosMatch15.6\(1\)t
OR
ciscoiosMatch15.6\(2\)t
OR
ciscoiosMatch15.6\(1\)t0a
OR
ciscoiosMatch15.6\(1\)t1
OR
ciscoiosMatch15.6\(2\)t1
OR
ciscoiosMatch15.6\(1\)t2
OR
ciscoiosMatch15.6\(2\)t2
OR
ciscoiosMatch15.6\(1\)t3
OR
ciscoiosMatch15.6\(2\)t3
OR
ciscoiosMatch15.6\(3\)m
OR
ciscoiosMatch15.6\(3\)m1
OR
ciscoiosMatch15.6\(3\)m0a
OR
ciscoiosMatch15.6\(3\)m1b
OR
ciscoiosMatch15.6\(3\)m2
OR
ciscoiosMatch15.6\(3\)m3
OR
ciscoiosMatch15.6\(3\)m3a
OR
ciscoiosMatch15.6\(3\)m4
OR
ciscoiosMatch15.6\(3\)m5
OR
ciscoiosMatch15.6\(3\)m6
OR
ciscoiosMatch15.6\(3\)m7
OR
ciscoiosMatch15.6\(3\)m6a
OR
ciscoiosMatch15.6\(3\)m6b
OR
ciscoiosMatch15.6\(3\)m8
OR
ciscoiosMatch15.7\(3\)m
OR
ciscoiosMatch15.7\(3\)m1
OR
ciscoiosMatch15.7\(3\)m0a
OR
ciscoiosMatch15.7\(3\)m3
OR
ciscoiosMatch15.7\(3\)m2
OR
ciscoiosMatch15.7\(3\)m4
OR
ciscoiosMatch15.7\(3\)m5
OR
ciscoiosMatch15.7\(3\)m4a
OR
ciscoiosMatch15.7\(3\)m4b
OR
ciscoiosMatch15.7\(3\)m6
OR
ciscoiosMatch15.8\(3\)m
OR
ciscoiosMatch15.8\(3\)m1
OR
ciscoiosMatch15.8\(3\)m0a
OR
ciscoiosMatch15.8\(3\)m2
OR
ciscoiosMatch15.8\(3\)m3
OR
ciscoiosMatch15.8\(3\)m2a
OR
ciscoiosMatch15.8\(3\)m4
OR
ciscoiosMatch15.8\(3\)m5
OR
ciscoiosMatch15.8\(3\)m6
OR
ciscoiosMatch15.8\(3\)m7
OR
ciscoiosMatch15.8\(3\)m8
OR
ciscoiosMatch15.8\(3\)m9
OR
ciscoiosMatch15.9\(3\)m
OR
ciscoiosMatch15.9\(3\)m1
OR
ciscoiosMatch15.9\(3\)m2
OR
ciscoiosMatch15.9\(3\)m3
OR
ciscoiosMatch15.9\(3\)m2a
OR
ciscoiosMatch15.9\(3\)m4
OR
ciscoiosMatch15.9\(3\)m5
OR
ciscoiosMatch15.9\(3\)m4a
OR
ciscoiosMatch15.9\(3\)m6
OR
ciscoiosMatch15.9\(3\)m6a
OR
ciscoiosMatch15.9\(3\)m6b
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch16.3.2
OR
ciscocisco_ios_xe_softwareMatch16.3.3
OR
ciscocisco_ios_xe_softwareMatch16.3.4
OR
ciscocisco_ios_xe_softwareMatch16.3.5
OR
ciscocisco_ios_xe_softwareMatch16.3.6
OR
ciscocisco_ios_xe_softwareMatch16.3.7
OR
ciscocisco_ios_xe_softwareMatch16.3.8
OR
ciscocisco_ios_xe_softwareMatch16.3.9
OR
ciscocisco_ios_xe_softwareMatch16.3.10
OR
ciscocisco_ios_xe_softwareMatch16.3.11
OR
ciscocisco_ios_xe_softwareMatch16.4.1
OR
ciscocisco_ios_xe_softwareMatch16.4.2
OR
ciscocisco_ios_xe_softwareMatch16.4.3
OR
ciscocisco_ios_xe_softwareMatch16.5.1
OR
ciscocisco_ios_xe_softwareMatch16.5.1b
OR
ciscocisco_ios_xe_softwareMatch16.5.2
OR
ciscocisco_ios_xe_softwareMatch16.5.3
OR
ciscocisco_ios_xe_softwareMatch16.6.1
OR
ciscocisco_ios_xe_softwareMatch16.6.2
OR
ciscocisco_ios_xe_softwareMatch16.6.3
OR
ciscocisco_ios_xe_softwareMatch16.6.4
OR
ciscocisco_ios_xe_softwareMatch16.6.5
OR
ciscocisco_ios_xe_softwareMatch16.6.4s
OR
ciscocisco_ios_xe_softwareMatch16.6.5a
OR
ciscocisco_ios_xe_softwareMatch16.6.6
OR
ciscocisco_ios_xe_softwareMatch16.6.5b
OR
ciscocisco_ios_xe_softwareMatch16.6.7
OR
ciscocisco_ios_xe_softwareMatch16.6.7a
OR
ciscocisco_ios_xe_softwareMatch16.6.8
OR
ciscocisco_ios_xe_softwareMatch16.6.9
OR
ciscocisco_ios_xe_softwareMatch16.6.10
OR
ciscocisco_ios_xe_softwareMatch16.7.1
OR
ciscocisco_ios_xe_softwareMatch16.7.2
OR
ciscocisco_ios_xe_softwareMatch16.7.3
OR
ciscocisco_ios_xe_softwareMatch16.8.1
OR
ciscocisco_ios_xe_softwareMatch16.8.1b
OR
ciscocisco_ios_xe_softwareMatch16.8.1s
OR
ciscocisco_ios_xe_softwareMatch16.8.1c
OR
ciscocisco_ios_xe_softwareMatch16.8.2
OR
ciscocisco_ios_xe_softwareMatch16.8.3
OR
ciscocisco_ios_xe_softwareMatch16.9.1
OR
ciscocisco_ios_xe_softwareMatch16.9.2
OR
ciscocisco_ios_xe_softwareMatch16.9.1a
OR
ciscocisco_ios_xe_softwareMatch16.9.1b
OR
ciscocisco_ios_xe_softwareMatch16.9.1s
OR
ciscocisco_ios_xe_softwareMatch16.9.1c
OR
ciscocisco_ios_xe_softwareMatch16.9.3
OR
ciscocisco_ios_xe_softwareMatch16.9.2a
OR
ciscocisco_ios_xe_softwareMatch16.9.2s
OR
ciscocisco_ios_xe_softwareMatch16.9.3h
OR
ciscocisco_ios_xe_softwareMatch16.9.4
OR
ciscocisco_ios_xe_softwareMatch16.9.3s
OR
ciscocisco_ios_xe_softwareMatch16.9.4c
OR
ciscocisco_ios_xe_softwareMatch16.9.5
OR
ciscocisco_ios_xe_softwareMatch16.9.5f
OR
ciscocisco_ios_xe_softwareMatch16.9.6
OR
ciscocisco_ios_xe_softwareMatch16.9.7
OR
ciscocisco_ios_xe_softwareMatch16.9.8
OR
ciscocisco_ios_xe_softwareMatch16.9.8a
OR
ciscocisco_ios_xe_softwareMatch16.9.8b
OR
ciscocisco_ios_xe_softwareMatch16.10.1
OR
ciscocisco_ios_xe_softwareMatch16.10.1a
OR
ciscocisco_ios_xe_softwareMatch16.10.1s
OR
ciscocisco_ios_xe_softwareMatch16.10.1e
OR
ciscocisco_ios_xe_softwareMatch16.10.2
OR
ciscocisco_ios_xe_softwareMatch16.10.3
OR
ciscocisco_ios_xe_softwareMatch16.11.1
OR
ciscocisco_ios_xe_softwareMatch16.11.1a
OR
ciscocisco_ios_xe_softwareMatch16.11.1b
OR
ciscocisco_ios_xe_softwareMatch16.11.2
OR
ciscocisco_ios_xe_softwareMatch16.11.1s
OR
ciscocisco_ios_xe_softwareMatch16.11.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1
OR
ciscocisco_ios_xe_softwareMatch16.12.1s
OR
ciscocisco_ios_xe_softwareMatch16.12.1a
OR
ciscocisco_ios_xe_softwareMatch16.12.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.2
OR
ciscocisco_ios_xe_softwareMatch16.12.2a
OR
ciscocisco_ios_xe_softwareMatch16.12.3
OR
ciscocisco_ios_xe_softwareMatch16.12.8
OR
ciscocisco_ios_xe_softwareMatch16.12.2s
OR
ciscocisco_ios_xe_softwareMatch16.12.2t
OR
ciscocisco_ios_xe_softwareMatch16.12.4
OR
ciscocisco_ios_xe_softwareMatch16.12.3s
OR
ciscocisco_ios_xe_softwareMatch16.12.5
OR
ciscocisco_ios_xe_softwareMatch16.12.6
OR
ciscocisco_ios_xe_softwareMatch16.12.5a
OR
ciscocisco_ios_xe_softwareMatch16.12.7
OR
ciscocisco_ios_xe_softwareMatch17.1.1
OR
ciscocisco_ios_xe_softwareMatch17.1.1a
OR
ciscocisco_ios_xe_softwareMatch17.1.1s
OR
ciscocisco_ios_xe_softwareMatch17.1.2
OR
ciscocisco_ios_xe_softwareMatch17.1.1t
OR
ciscocisco_ios_xe_softwareMatch17.1.3
OR
ciscocisco_ios_xe_softwareMatch17.2.1
OR
ciscocisco_ios_xe_softwareMatch17.2.1r
OR
ciscocisco_ios_xe_softwareMatch17.2.1v
OR
ciscocisco_ios_xe_softwareMatch17.2.2
OR
ciscocisco_ios_xe_softwareMatch17.2.3
OR
ciscocisco_ios_xe_softwareMatch17.3.5a
OR
ciscocisco_ios_xe_softwareMatch17.3.5b
OR
ciscocisco_ios_xe_softwareMatch17.4.1
OR
ciscocisco_ios_xe_softwareMatch17.4.2
OR
ciscocisco_ios_xe_softwareMatch17.4.1a
OR
ciscocisco_ios_xe_softwareMatch17.4.1b
OR
ciscocisco_ios_xe_softwareMatch17.4.1c
OR
ciscocisco_ios_xe_softwareMatch17.5.1
OR
ciscocisco_ios_xe_softwareMatch17.5.1a
OR
ciscocisco_ios_xe_softwareMatch17.6.1
OR
ciscocisco_ios_xe_softwareMatch17.6.2
OR
ciscocisco_ios_xe_softwareMatch17.6.1a
OR
ciscocisco_ios_xe_softwareMatch17.6.3
OR
ciscocisco_ios_xe_softwareMatch17.6.3a
OR
ciscocisco_ios_xe_softwareMatch17.6.4
OR
ciscocisco_ios_xe_softwareMatch17.7.1
OR
ciscocisco_ios_xe_softwareMatch17.7.1a
OR
ciscocisco_ios_xe_softwareMatch17.7.1b
OR
ciscocisco_ios_xe_softwareMatch17.7.2
OR
ciscocisco_ios_xe_softwareMatch17.8.1
OR
ciscocisco_ios_xe_softwareMatch17.8.1a
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoic3000_industrial_compute_gatewayMatchany
OR
ciscoir510_operating_systemMatchany
OR
ciscocgr1000_compute_moduleMatchany
VendorProductVersionCPE
ciscoios15.6tcpe:2.3:o:cisco:ios:15.6t:*:*:*:*:*:*:*
ciscoios15.6mcpe:2.3:o:cisco:ios:15.6m:*:*:*:*:*:*:*
ciscoios15.7mcpe:2.3:o:cisco:ios:15.7m:*:*:*:*:*:*:*
ciscoios15.8mcpe:2.3:o:cisco:ios:15.8m:*:*:*:*:*:*:*
ciscoios15.9mcpe:2.3:o:cisco:ios:15.9m:*:*:*:*:*:*:*
ciscoiosanycpe:2.3:o:cisco:ios:any:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.3cpe:2.3:a:cisco:cisco_ios_xe_software:16.3:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.4cpe:2.3:a:cisco:cisco_ios_xe_software:16.4:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.5cpe:2.3:a:cisco:cisco_ios_xe_software:16.5:*:*:*:*:*:*:*
ciscocisco_ios_xe_software16.6cpe:2.3:a:cisco:cisco_ios_xe_software:16.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 2041

EPSS

0.003

Percentile

70.0%

Related for CISCO-SA-IOX-8WHGN5DL