ID

VAR-201707-0929


CVE

CVE-2017-6719


TITLE

Cisco IOS XR Software CLI In root An arbitrary command execution vulnerability on a privileged host operating system

Trust: 0.8

sources: JVNDB: JVNDB-2017-005310

DESCRIPTION

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. Cisco IOSXRSoftware has a security vulnerability in the CLI implementation. This issue is being tracked by Cisco bug ID CSCvb99406. Cisco IOS XR Software is a set of completely modularized and distributed network operating systems in Cisco's IOS software series (including IOS T, IOS S and IOS XR)

Trust: 2.52

sources: NVD: CVE-2017-6719 // JVNDB: JVNDB-2017-005310 // CNVD: CNVD-2017-11545 // BID: 99213 // VULHUB: VHN-114922

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-11545

AFFECTED PRODUCTS

vendor:ciscomodel:ios xrscope:eqversion:6.0.2.01

Trust: 1.6

vendor:ciscomodel:ios xrscope:eqversion:6.0.2

Trust: 1.6

vendor:ciscomodel:ios xrscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xr softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:network convergence system series 6.2.1.basescope:eqversion:5000

Trust: 0.3

vendor:ciscomodel:ios xr software 6.0.2.basescope: - version: -

Trust: 0.3

vendor:ciscomodel:network convergence system series 6.2.1.28i.basescope:neversion:5000

Trust: 0.3

vendor:ciscomodel:network convergence system series 6.2.1.22i.basescope:neversion:5000

Trust: 0.3

vendor:ciscomodel:network convergence system series 6.1.32.8i.basescope:neversion:5000

Trust: 0.3

vendor:ciscomodel:network convergence system series 6.1.31.3i.basescope:neversion:5000

Trust: 0.3

vendor:ciscomodel:network convergence system series 6.1.3.10i.basescope:neversion:5000

Trust: 0.3

sources: CNVD: CNVD-2017-11545 // BID: 99213 // JVNDB: JVNDB-2017-005310 // CNNVD: CNNVD-201706-1008 // NVD: CVE-2017-6719

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6719
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6719
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-11545
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201706-1008
value: HIGH

Trust: 0.6

VULHUB: VHN-114922
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-6719
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-11545
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-114922
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6719
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-11545 // VULHUB: VHN-114922 // JVNDB: JVNDB-2017-005310 // CNNVD: CNNVD-201706-1008 // NVD: CVE-2017-6719

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-114922 // JVNDB: JVNDB-2017-005310 // NVD: CVE-2017-6719

THREAT TYPE

local

Trust: 0.9

sources: BID: 99213 // CNNVD: CNNVD-201706-1008

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201706-1008

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-005310

PATCH

title:cisco-sa-20170621-iosurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios

Trust: 0.8

title:Cisco IOSXRSoftware Local Command Injection Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/96502

Trust: 0.6

title:Cisco IOS XR Software Fixes for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=71197

Trust: 0.6

sources: CNVD: CNVD-2017-11545 // JVNDB: JVNDB-2017-005310 // CNNVD: CNNVD-201706-1008

EXTERNAL IDS

db:NVDid:CVE-2017-6719

Trust: 3.4

db:BIDid:99213

Trust: 2.0

db:SECTRACKid:1038741

Trust: 1.1

db:JVNDBid:JVNDB-2017-005310

Trust: 0.8

db:CNNVDid:CNNVD-201706-1008

Trust: 0.7

db:CNVDid:CNVD-2017-11545

Trust: 0.6

db:NSFOCUSid:36958

Trust: 0.6

db:VULHUBid:VHN-114922

Trust: 0.1

sources: CNVD: CNVD-2017-11545 // VULHUB: VHN-114922 // BID: 99213 // JVNDB: JVNDB-2017-005310 // CNNVD: CNNVD-201706-1008 // NVD: CVE-2017-6719

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170621-ios

Trust: 2.6

url:http://www.securityfocus.com/bid/99213

Trust: 1.7

url:http://www.securitytracker.com/id/1038741

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6719

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6719

Trust: 0.8

url:http://www.nsfocus.net/vulndb/36958

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2017-11545 // VULHUB: VHN-114922 // BID: 99213 // JVNDB: JVNDB-2017-005310 // CNNVD: CNNVD-201706-1008 // NVD: CVE-2017-6719

CREDITS

Cisco

Trust: 0.9

sources: BID: 99213 // CNNVD: CNNVD-201706-1008

SOURCES

db:CNVDid:CNVD-2017-11545
db:VULHUBid:VHN-114922
db:BIDid:99213
db:JVNDBid:JVNDB-2017-005310
db:CNNVDid:CNNVD-201706-1008
db:NVDid:CVE-2017-6719

LAST UPDATE DATE

2024-11-23T22:52:24.407000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-11545date:2017-06-27T00:00:00
db:VULHUBid:VHN-114922date:2017-07-07T00:00:00
db:BIDid:99213date:2017-06-21T00:00:00
db:JVNDBid:JVNDB-2017-005310date:2017-07-26T00:00:00
db:CNNVDid:CNNVD-201706-1008date:2017-07-04T00:00:00
db:NVDid:CVE-2017-6719date:2024-11-21T03:30:22.487

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-11545date:2017-06-27T00:00:00
db:VULHUBid:VHN-114922date:2017-07-04T00:00:00
db:BIDid:99213date:2017-06-21T00:00:00
db:JVNDBid:JVNDB-2017-005310date:2017-07-26T00:00:00
db:CNNVDid:CNNVD-201706-1008date:2017-06-23T00:00:00
db:NVDid:CVE-2017-6719date:2017-07-04T00:29:00.650