Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106282
Category:CISCO
Title:Cisco IOS Software iox Command Injection Vulnerability
Summary:A vulnerability exists in the iox command in Cisco IOS Software that;could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating;system (GOS).
Description:Summary:
A vulnerability exists in the iox command in Cisco IOS Software that
could allow an authenticated, local attacker to perform command injection into the IOx Linux guest operating
system (GOS).

Vulnerability Insight:
This vulnerability is due to insufficient input validation of iox command
line arguments. An attacker could exploit this vulnerability by providing crafted options to the iox command.

Vulnerability Impact:
An exploit could allow the attacker to execute commands of their choice in
the Linux GOS.

Solution:
Upgrade to version 15.6(3.0q)M or later.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6414
BugTraq ID: 93091
http://www.securityfocus.com/bid/93091
Cisco Security Advisory: 20160921 Cisco IOS and IOS XE iox Command Injection Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-iox
http://www.securitytracker.com/id/1036876
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.