← Back

CVE-2017-6707

nvd nist
Published: Jul 6, 2017Modified: May 13, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: NVD

Description

A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the StarOS CLI of an affected system and execute arbitrary shell commands as a Linux root user on the system, aka Command Injection. The vulnerability exists because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this vulnerability by submitting a crafted CLI command for execution in a Linux shell command as a root user. Cisco Bug IDs: CSCvc69329, CSCvc72930.

Affected (58)

Products: Cisco: Staros
1 product
Staros
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 11.0_base
Version 12.0.0
Version 12.1_base
Version 12.2(300)
Version 12.2_base
Version 14.0.0
Version 14.0(600)
Version 15.0(912)
Version 15.0(935)
Version 15.0(938)
Version 15.0_base
Version 16.0.0
Version 16.0(900)
Version 16.1.0
Version 16.1.1
Version 16.1.2
Version 16.5.0
Version 16.5.2
Version 17.2.0.59184
Version 17.2.0
Version 17.3.0
Version 17.3.1
Version 17.3_base
Version 17.7.0
Version 18.0.0.57828
Version 18.0.0.59167
Version 18.0.0.59211
Version 18.0.0
Version 18.0.l0.59219
Version 18.1.0.59776
Version 18.1.0.59780
Version 18.1.0
Version 18.1_base
Version 18.3.0
Version 18.3_base
Version 18.4.0
Version 19.0.1
Version 19.0.m0.60737
Version 19.0.m0.60828
Version 19.0.m0.61045
Version 19.1.0.61559
Version 19.1.0
Version 19.2.0
Version 19.3.0
Version 20.0.0
Version 20.0.1.0
Version 20.0.1.a0
Version 20.0.1.v0
Version 20.0.2.3.65026
Version 20.0.2.3
Version 20.0.2.v1
Version 20.0.m0.62842
Version 20.0.m0.63229
Version 20.0.v0
Version 21.0.0
Version 21.0_base
Version 21.0_m0.64246
Version 21.0_m0.64702

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.