Lucene search

K
ciscoCiscoCISCO-SA-XE-FSM-YJ8QJBJC
HistoryMar 24, 2021 - 4:00 p.m.

Cisco IOS and IOS XE Software Privilege Escalation Vulnerability

2021-03-2416:00:00
tools.cisco.com
77
cisco
ios
xe software
privilege escalation
vulnerability
local attacker
root privilege
development testing
consent token
software updates
security advisory

EPSS

0

Percentile

5.1%

A vulnerability in the dragonite debugger of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege.

The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consent token mechanism with the residual scripts on the affected device. A successful exploit could allow the attacker to escalate from privilege level 15 to root privilege.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-FSM-Yj8qJbJc [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-XE-FSM-Yj8qJbJc”]

Affected configurations

Vulners
Node
ciscoiosMatch15.0se
OR
ciscoiosMatch15.2e
OR
ciscoiosMatch15.2ex
OR
ciscoiosMatch15.2eb
OR
ciscoiosMatch15.2ea
OR
ciscoiosMatch15.3jf
OR
ciscoiosMatch12.2i
OR
ciscoiosMatch15.1svr
OR
ciscoiosMatch15.1svs
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch3.9e
OR
ciscocisco_ios_xe_softwareMatch16.8
OR
ciscocisco_ios_xe_softwareMatch16.9
OR
ciscocisco_ios_xe_softwareMatch16.10
OR
ciscocisco_ios_xe_softwareMatch3.10e
OR
ciscocisco_ios_xe_softwareMatch16.11
OR
ciscocisco_ios_xe_softwareMatch16.12
OR
ciscocisco_ios_xe_softwareMatch3.11e
OR
ciscocisco_ios_xe_softwareMatch17.1
OR
ciscocisco_ios_xe_softwareMatch17.2
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoiosMatch15.0\(2\)se13a
OR
ciscoiosMatch15.2\(5\)e
OR
ciscoiosMatch15.2\(5a\)e
OR
ciscoiosMatch15.2\(5\)e1
OR
ciscoiosMatch15.2\(5b\)e
OR
ciscoiosMatch15.2\(5c\)e
OR
ciscoiosMatch15.2\(5a\)e1
OR
ciscoiosMatch15.2\(5\)e2
OR
ciscoiosMatch15.2\(6\)e
OR
ciscoiosMatch15.2\(5\)e2b
OR
ciscoiosMatch15.2\(5\)e2c
OR
ciscoiosMatch15.2\(6\)e0a
OR
ciscoiosMatch15.2\(6\)e1
OR
ciscoiosMatch15.2\(6\)e0c
OR
ciscoiosMatch15.2\(6\)e2
OR
ciscoiosMatch15.2\(6\)e1a
OR
ciscoiosMatch15.2\(6\)e1s
OR
ciscoiosMatch15.2\(7\)e
OR
ciscoiosMatch15.2\(6\)e2a
OR
ciscoiosMatch15.2\(6\)e2b
OR
ciscoiosMatch15.2\(7\)e1
OR
ciscoiosMatch15.2\(7\)e0a
OR
ciscoiosMatch15.2\(7\)e0b
OR
ciscoiosMatch15.2\(7\)e0s
OR
ciscoiosMatch15.2\(6\)e3
OR
ciscoiosMatch15.2\(7\)e2
OR
ciscoiosMatch15.2\(7a\)e0b
OR
ciscoiosMatch15.2\(7\)e3
OR
ciscoiosMatch15.2\(7\)e1a
OR
ciscoiosMatch15.2\(7b\)e0b
OR
ciscoiosMatch15.2\(7\)e2a
OR
ciscoiosMatch15.2\(7\)e2b
OR
ciscoiosMatch15.2\(7\)e3k
OR
ciscoiosMatch15.2\(5\)ex
OR
ciscoiosMatch15.2\(6\)eb
OR
ciscoiosMatch15.2\(5\)ea
OR
ciscoiosMatch15.2\(4\)ea10
OR
ciscoiosMatch15.3\(3\)jf13
OR
ciscoiosMatch12.2\(6\)i1
OR
ciscoiosMatch15.1\(3\)svr1
OR
ciscoiosMatch15.1\(3\)svr2
OR
ciscoiosMatch15.1\(3\)svr3
OR
ciscoiosMatch15.1\(3\)svs
OR
ciscoiosMatch15.1\(3\)svs1
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch3.9.0e
OR
ciscocisco_ios_xe_softwareMatch3.9.1e
OR
ciscocisco_ios_xe_softwareMatch3.9.2e
OR
ciscocisco_ios_xe_softwareMatch3.9.2be
OR
ciscocisco_ios_xe_softwareMatch16.8.1
OR
ciscocisco_ios_xe_softwareMatch16.8.1a
OR
ciscocisco_ios_xe_softwareMatch16.8.1b
OR
ciscocisco_ios_xe_softwareMatch16.8.1s
OR
ciscocisco_ios_xe_softwareMatch16.8.1c
OR
ciscocisco_ios_xe_softwareMatch16.8.1d
OR
ciscocisco_ios_xe_softwareMatch16.8.2
OR
ciscocisco_ios_xe_softwareMatch16.8.1e
OR
ciscocisco_ios_xe_softwareMatch16.8.3
OR
ciscocisco_ios_xe_softwareMatch16.9.1
OR
ciscocisco_ios_xe_softwareMatch16.9.2
OR
ciscocisco_ios_xe_softwareMatch16.9.1a
OR
ciscocisco_ios_xe_softwareMatch16.9.1b
OR
ciscocisco_ios_xe_softwareMatch16.9.1s
OR
ciscocisco_ios_xe_softwareMatch16.9.1c
OR
ciscocisco_ios_xe_softwareMatch16.9.1d
OR
ciscocisco_ios_xe_softwareMatch16.9.3
OR
ciscocisco_ios_xe_softwareMatch16.9.2a
OR
ciscocisco_ios_xe_softwareMatch16.9.2s
OR
ciscocisco_ios_xe_softwareMatch16.9.3h
OR
ciscocisco_ios_xe_softwareMatch16.9.4
OR
ciscocisco_ios_xe_softwareMatch16.9.3s
OR
ciscocisco_ios_xe_softwareMatch16.9.3a
OR
ciscocisco_ios_xe_softwareMatch16.9.4c
OR
ciscocisco_ios_xe_softwareMatch16.9.5
OR
ciscocisco_ios_xe_softwareMatch16.9.5f
OR
ciscocisco_ios_xe_softwareMatch16.9.6
OR
ciscocisco_ios_xe_softwareMatch16.10.1
OR
ciscocisco_ios_xe_softwareMatch16.10.1a
OR
ciscocisco_ios_xe_softwareMatch16.10.1b
OR
ciscocisco_ios_xe_softwareMatch16.10.1s
OR
ciscocisco_ios_xe_softwareMatch16.10.1c
OR
ciscocisco_ios_xe_softwareMatch16.10.1e
OR
ciscocisco_ios_xe_softwareMatch16.10.1d
OR
ciscocisco_ios_xe_softwareMatch16.10.2
OR
ciscocisco_ios_xe_softwareMatch16.10.1f
OR
ciscocisco_ios_xe_softwareMatch16.10.1g
OR
ciscocisco_ios_xe_softwareMatch16.10.3
OR
ciscocisco_ios_xe_softwareMatch3.10.0e
OR
ciscocisco_ios_xe_softwareMatch3.10.1e
OR
ciscocisco_ios_xe_softwareMatch3.10.0ce
OR
ciscocisco_ios_xe_softwareMatch3.10.2e
OR
ciscocisco_ios_xe_softwareMatch3.10.1ae
OR
ciscocisco_ios_xe_softwareMatch3.10.1se
OR
ciscocisco_ios_xe_softwareMatch3.10.3e
OR
ciscocisco_ios_xe_softwareMatch16.11.1
OR
ciscocisco_ios_xe_softwareMatch16.11.1a
OR
ciscocisco_ios_xe_softwareMatch16.11.1b
OR
ciscocisco_ios_xe_softwareMatch16.11.2
OR
ciscocisco_ios_xe_softwareMatch16.11.1s
OR
ciscocisco_ios_xe_softwareMatch16.11.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1
OR
ciscocisco_ios_xe_softwareMatch16.12.1s
OR
ciscocisco_ios_xe_softwareMatch16.12.1a
OR
ciscocisco_ios_xe_softwareMatch16.12.1c
OR
ciscocisco_ios_xe_softwareMatch16.12.1w
OR
ciscocisco_ios_xe_softwareMatch16.12.2
OR
ciscocisco_ios_xe_softwareMatch16.12.1y
OR
ciscocisco_ios_xe_softwareMatch16.12.2a
OR
ciscocisco_ios_xe_softwareMatch16.12.3
OR
ciscocisco_ios_xe_softwareMatch16.12.2s
OR
ciscocisco_ios_xe_softwareMatch16.12.1x
OR
ciscocisco_ios_xe_softwareMatch16.12.1t
OR
ciscocisco_ios_xe_softwareMatch16.12.2t
OR
ciscocisco_ios_xe_softwareMatch16.12.3s
OR
ciscocisco_ios_xe_softwareMatch16.12.1z
OR
ciscocisco_ios_xe_softwareMatch16.12.3a
OR
ciscocisco_ios_xe_softwareMatch16.12.1z2
OR
ciscocisco_ios_xe_softwareMatch3.11.0e
OR
ciscocisco_ios_xe_softwareMatch3.11.1e
OR
ciscocisco_ios_xe_softwareMatch3.11.2e
OR
ciscocisco_ios_xe_softwareMatch3.11.3e
OR
ciscocisco_ios_xe_softwareMatch3.11.1ae
OR
ciscocisco_ios_xe_softwareMatch3.11.2ae
OR
ciscocisco_ios_xe_softwareMatch3.11.3ae
OR
ciscocisco_ios_xe_softwareMatch17.1.1
OR
ciscocisco_ios_xe_softwareMatch17.1.1a
OR
ciscocisco_ios_xe_softwareMatch17.1.1s
OR
ciscocisco_ios_xe_softwareMatch17.1.2
OR
ciscocisco_ios_xe_softwareMatch17.1.1t
OR
ciscocisco_ios_xe_softwareMatch17.2.1
OR
ciscocisco_ios_xe_softwareMatch17.2.1r
OR
ciscocisco_ios_xe_softwareMatch17.2.1a
OR
ciscocisco_ios_xe_softwareMatch17.2.1v
OR
ciscocisco_ios_xe_softwareMatch17.2.2
OR
ciscocisco_ios_xe_softwareMatchany
VendorProductVersionCPE
ciscoios15.0secpe:2.3:o:cisco:ios:15.0se:*:*:*:*:*:*:*
ciscoios15.2ecpe:2.3:o:cisco:ios:15.2e:*:*:*:*:*:*:*
ciscoios15.2excpe:2.3:o:cisco:ios:15.2ex:*:*:*:*:*:*:*
ciscoios15.2ebcpe:2.3:o:cisco:ios:15.2eb:*:*:*:*:*:*:*
ciscoios15.2eacpe:2.3:o:cisco:ios:15.2ea:*:*:*:*:*:*:*
ciscoios15.3jfcpe:2.3:o:cisco:ios:15.3jf:*:*:*:*:*:*:*
ciscoios12.2icpe:2.3:o:cisco:ios:12.2i:*:*:*:*:*:*:*
ciscoios15.1svrcpe:2.3:o:cisco:ios:15.1svr:*:*:*:*:*:*:*
ciscoios15.1svscpe:2.3:o:cisco:ios:15.1svs:*:*:*:*:*:*:*
ciscoiosanycpe:2.3:o:cisco:ios:any:*:*:*:*:*:*:*
Rows per page:
1-10 of 1541

EPSS

0

Percentile

5.1%

Related for CISCO-SA-XE-FSM-YJ8QJBJC