Lucene search

K
ciscoCiscoCISCO-SA-WEBUI-CMDIJ-FZZAEXAY
HistorySep 27, 2023 - 4:00 p.m.

Cisco IOS XE Software Web UI Command Injection Vulnerability

2023-09-2716:00:00
tools.cisco.com
30
cisco ios xe
web ui
command injection
vulnerability
remote attacker
arbitrary commands
input validation
software update
cisco event response

0.001 Low

EPSS

Percentile

23.8%

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.

This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary Cisco IOS XE Software CLI commands with level 15 privileges.

Note: This vulnerability is exploitable only if the attacker obtains the credentials for a Lobby Ambassador account. This account is not configured by default.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy”]

This advisory is part of the September 2023 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2023 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [“https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-74916”].

Affected configurations

Vulners
Node
ciscocisco_iosMatch16.12xe
OR
ciscocisco_iosMatch17.2xe
OR
ciscocisco_iosMatch17.3xe
OR
ciscocisco_iosMatch17.4xe
OR
ciscocisco_iosMatch17.5xe
OR
ciscocisco_iosMatch17.6xe
OR
ciscocisco_iosMatch17.7xe
OR
ciscocisco_iosMatch17.10xe
OR
ciscocisco_iosMatch17.8xe
OR
ciscocisco_iosMatch17.9xe
OR
ciscocisco_iosMatchanyxe
OR
ciscocisco_iosMatch16.12.8xe
OR
ciscocisco_iosMatch16.12.4xe
OR
ciscocisco_iosMatch16.12.4axe
OR
ciscocisco_iosMatch16.12.5xe
OR
ciscocisco_iosMatch16.12.6xe
OR
ciscocisco_iosMatch16.12.5axe
OR
ciscocisco_iosMatch16.12.5bxe
OR
ciscocisco_iosMatch16.12.6axe
OR
ciscocisco_iosMatch16.12.7xe
OR
ciscocisco_iosMatch16.12.9xe
OR
ciscocisco_iosMatch17.2.2xe
OR
ciscocisco_iosMatch17.2.3xe
OR
ciscocisco_iosMatch17.3.1xe
OR
ciscocisco_iosMatch17.3.2xe
OR
ciscocisco_iosMatch17.3.3xe
OR
ciscocisco_iosMatch17.3.1axe
OR
ciscocisco_iosMatch17.3.1wxe
OR
ciscocisco_iosMatch17.3.2axe
OR
ciscocisco_iosMatch17.3.1xxe
OR
ciscocisco_iosMatch17.3.1zxe
OR
ciscocisco_iosMatch17.3.3axe
OR
ciscocisco_iosMatch17.3.4xe
OR
ciscocisco_iosMatch17.3.5xe
OR
ciscocisco_iosMatch17.3.4axe
OR
ciscocisco_iosMatch17.3.6xe
OR
ciscocisco_iosMatch17.3.4bxe
OR
ciscocisco_iosMatch17.3.4cxe
OR
ciscocisco_iosMatch17.3.5axe
OR
ciscocisco_iosMatch17.3.5bxe
OR
ciscocisco_iosMatch17.4.1xe
OR
ciscocisco_iosMatch17.4.2xe
OR
ciscocisco_iosMatch17.4.1axe
OR
ciscocisco_iosMatch17.4.1bxe
OR
ciscocisco_iosMatch17.4.1cxe
OR
ciscocisco_iosMatch17.4.2axe
OR
ciscocisco_iosMatch17.5.1xe
OR
ciscocisco_iosMatch17.5.1axe
OR
ciscocisco_iosMatch17.5.1bxe
OR
ciscocisco_iosMatch17.5.1cxe
OR
ciscocisco_iosMatch17.6.1xe
OR
ciscocisco_iosMatch17.6.2xe
OR
ciscocisco_iosMatch17.6.1wxe
OR
ciscocisco_iosMatch17.6.1axe
OR
ciscocisco_iosMatch17.6.1xxe
OR
ciscocisco_iosMatch17.6.3xe
OR
ciscocisco_iosMatch17.6.1yxe
OR
ciscocisco_iosMatch17.6.1zxe
OR
ciscocisco_iosMatch17.6.3axe
OR
ciscocisco_iosMatch17.6.4xe
OR
ciscocisco_iosMatch17.6.1z1xe
OR
ciscocisco_iosMatch17.6.5xe
OR
ciscocisco_iosMatch17.6.5axe
OR
ciscocisco_iosMatch17.7.1xe
OR
ciscocisco_iosMatch17.7.1axe
OR
ciscocisco_iosMatch17.7.1bxe
OR
ciscocisco_iosMatch17.7.2xe
OR
ciscocisco_iosMatch17.10.1xe
OR
ciscocisco_iosMatch17.10.1axe
OR
ciscocisco_iosMatch17.10.1bxe
OR
ciscocisco_iosMatch17.8.1xe
OR
ciscocisco_iosMatch17.8.1axe
OR
ciscocisco_iosMatch17.9.1xe
OR
ciscocisco_iosMatch17.9.1wxe
OR
ciscocisco_iosMatch17.9.2xe
OR
ciscocisco_iosMatch17.9.1axe
OR
ciscocisco_iosMatch17.9.1xxe
OR
ciscocisco_iosMatch17.9.1yxe
OR
ciscocisco_iosMatch17.9.2axe
OR
ciscocisco_iosMatch17.9.1x1xe
OR
ciscocisco_iosMatchanyxe

0.001 Low

EPSS

Percentile

23.8%

Related for CISCO-SA-WEBUI-CMDIJ-FZZAEXAY