Lucene search

K
ciscoCiscoCISCO-SA-NGWC-CMDINJ-KEWWVWR
HistoryJun 03, 2020 - 4:00 p.m.

Cisco IOS XE Software Command Injection Vulnerability

2020-06-0316:00:00
tools.cisco.com
16

0.0004 Low

EPSS

Percentile

5.2%

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot.

This vulnerability is due to insufficient input validation checks while processing boot options. An attacker could exploit this vulnerability by modifying device boot options to execute attacker-provided code. A successful exploit may allow an attacker to bypass the Secure Boot process and execute malicious code on an affected device with root-level privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngwc-cmdinj-KEwWVWR [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngwc-cmdinj-KEwWVWR”]

This advisory is part of the June 3, 2020, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 23 Cisco Security Advisories that describe 25 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: June 2020 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [" https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-73388"].

Affected configurations

Vulners
Node
ciscocisco_iosMatch16.9xe
OR
ciscocisco_iosMatch16.10xe
OR
ciscocisco_iosMatch16.11xe
OR
ciscocisco_iosMatch16.12xe
OR
ciscocisco_iosMatch16.9.2xe
OR
ciscocisco_iosMatch16.9.3xe
OR
ciscocisco_iosMatch16.9.2axe
OR
ciscocisco_iosMatch16.9.2sxe
OR
ciscocisco_iosMatch16.9.3hxe
OR
ciscocisco_iosMatch16.9.4xe
OR
ciscocisco_iosMatch16.9.3sxe
OR
ciscocisco_iosMatch16.9.3axe
OR
ciscocisco_iosMatch16.10.1xe
OR
ciscocisco_iosMatch16.10.1sxe
OR
ciscocisco_iosMatch16.10.1exe
OR
ciscocisco_iosMatch16.11.1xe
OR
ciscocisco_iosMatch16.11.1axe
OR
ciscocisco_iosMatch16.11.1bxe
OR
ciscocisco_iosMatch16.11.2xe
OR
ciscocisco_iosMatch16.11.1sxe
OR
ciscocisco_iosMatch16.11.1cxe
OR
ciscocisco_iosMatch16.12.1xe
OR
ciscocisco_iosMatch16.12.1sxe
OR
ciscocisco_iosMatch16.12.1cxe

0.0004 Low

EPSS

Percentile

5.2%

Related for CISCO-SA-NGWC-CMDINJ-KEWWVWR