Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106689
Category:CISCO
Title:Cisco IOS XE Software HTTP Command Injection Vulnerability
Summary:A vulnerability in the web framework of Cisco IOS XE Software could allow an;authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.
Description:Summary:
A vulnerability in the web framework of Cisco IOS XE Software could allow an
authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.

Vulnerability Insight:
The vulnerability is due to insufficient input validation of HTTP parameters
supplied by the user. An attacker could exploit this vulnerability by authenticating to the device and submitting
crafted input to the affected web page parameter. The user must be authenticated to access the affected
parameter.

Vulnerability Impact:
A successful exploit could allow the attacker to execute commands with root
privileges.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-3858
BugTraq ID: 97009
http://www.securityfocus.com/bid/97009
http://www.securitytracker.com/id/1038102
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.