Lucene search

K
cveCiscoCVE-2018-0224
HistoryMar 08, 2018 - 7:29 a.m.

CVE-2018-0224

2018-03-0807:29:01
CWE-78
CWE-77
cisco
web.nvd.nist.gov
34
cve-2018-0224
cisco
staros
asr 5000
vulnerability
cli
root privileges
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

19.8%

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by authenticating to an affected system and injecting malicious arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected system. Cisco Bug IDs: CSCvg38807.

Affected configurations

Nvd
Node
ciscostarosMatch21.3.0.67664
OR
ciscostarosMatch21.5.0
AND
ciscoasr_5000Match-
OR
ciscoasr_5500Match-
OR
ciscoasr_5700Match-
VendorProductVersionCPE
ciscostaros21.3.0.67664cpe:2.3:o:cisco:staros:21.3.0.67664:*:*:*:*:*:*:*
ciscostaros21.5.0cpe:2.3:o:cisco:staros:21.5.0:*:*:*:*:*:*:*
ciscoasr_5000-cpe:2.3:h:cisco:asr_5000:-:*:*:*:*:*:*:*
ciscoasr_5500-cpe:2.3:h:cisco:asr_5500:-:*:*:*:*:*:*:*
ciscoasr_5700-cpe:2.3:h:cisco:asr_5700:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco StarOS",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco StarOS"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

19.8%

Related for CVE-2018-0224