Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106391
Category:CISCO
Title:Cisco IOS XE Software Directory Traversal Vulnerability
Summary:A vulnerability in the package unbundle utility of Cisco IOS XE Software;could allow an authenticated, local attacker to gain write access to some files in the underlying operating;system.
Description:Summary:
A vulnerability in the package unbundle utility of Cisco IOS XE Software
could allow an authenticated, local attacker to gain write access to some files in the underlying operating
system.

Vulnerability Insight:
The vulnerability is due to insufficient validation of files submitted to
the affected installation utility. An attacker could exploit this vulnerability by uploading a crafted file to
an affected system and running the installation utility command.

Vulnerability Impact:
A successful exploit could allow the attacker to gain write access to some
files in the underlying operating system, which could allow the attacker to override the write-accessible files
and compromise the integrity of the system.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
1.9

CVSS Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6450
BugTraq ID: 94340
http://www.securityfocus.com/bid/94340
http://www.securitytracker.com/id/1037299
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.