← Back

CVE-2018-0183

nvd nist
Published: Mar 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit this vulnerability on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCuv91356.

Affected (11)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.13.2as
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.13.5as
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.13.7as
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.13.9s
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.16.2as
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.16.2bs
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.16.3s
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.3.5b
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.3.6
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.13.0as
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.6.3

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.