Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2021-04935

Опубликовано: 22 сент. 2021
Источник: fstec
CVSS3: 7.7
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость синтаксического анализатора командной строки TrustSec CLI операционных систем Cisco IOS XE и Cisco IOS связана с неправильным взаимодействием веб-интерфейса пользователя и интерфейса командной строки. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, вызвать отказ в обслуживании с помощью специально созданной команды

Вендор

Cisco Systems Inc.

Наименование ПО

Cisco IOS XE
Cisco IOS

Версия ПО

16.1 (Cisco IOS XE)
16.2 (Cisco IOS XE)
3.3XO (Cisco IOS XE)
3.7E (Cisco IOS XE)
3.9E (Cisco IOS XE)
3.15S (Cisco IOS XE)
3.16S (Cisco IOS XE)
3.17S (Cisco IOS XE)
16.11 (Cisco IOS XE)
3.3SE (Cisco IOS XE)
3.5E (Cisco IOS XE)
3.6E (Cisco IOS XE)
3.14S (Cisco IOS XE)
3.18S (Cisco IOS XE)
3.18SP (Cisco IOS XE)
3.10E (Cisco IOS XE)
15.0EY (Cisco IOS)
15.0EX (Cisco IOS)
15.1SY (Cisco IOS)
15.4S (Cisco IOS)
15.2SY (Cisco IOS)
15.5S (Cisco IOS)
15.3SY (Cisco IOS)
15.6SP (Cisco IOS)
15.4SY (Cisco IOS)
15.5SY (Cisco IOS)
15.7M (Cisco IOS)
15.8M (Cisco IOS)
15.4T (Cisco IOS)
15.4M (Cisco IOS)
15.4CG (Cisco IOS)
15.5T (Cisco IOS)
15.4SN (Cisco IOS)
15.5M (Cisco IOS)
15.5SN (Cisco IOS)
15.6S (Cisco IOS)
15.6T (Cisco IOS)
15.5XB (Cisco IOS)
15.6SN (Cisco IOS)
15.3JD (Cisco IOS)
15.6M (Cisco IOS)
15.3JE (Cisco IOS)
15.3JF (Cisco IOS)
15.3JG (Cisco IOS)
15.3JH (Cisco IOS)
15.3JI (Cisco IOS)
15.3JJ (Cisco IOS)
15.2E (Cisco IOS)
16.12 (Cisco IOS XE)
15.0SE (Cisco IOS)
15.0EZ (Cisco IOS)
15.2EY (Cisco IOS)
15.0EJ (Cisco IOS)
15.2EX (Cisco IOS)
15.0EK (Cisco IOS)
15.2EB (Cisco IOS)
15.2EA (Cisco IOS)
15.2EC (Cisco IOS)
12.2I (Cisco IOS)
15.9M (Cisco IOS)
15.3JPI (Cisco IOS)
15.1SVS (Cisco IOS)
3.11E (Cisco IOS XE)
15.3JPJ (Cisco IOS)
15.3JK (Cisco IOS)
15.1SVR (Cisco IOS)
от 16.3 до 16.5 включительно (Cisco IOS XE)
от 16.6 до 16.10 включительно (Cisco IOS XE)
15.1SVT (Cisco IOS)
15.3JPK (Cisco IOS)
от 3.11S до 3.13S включительно (Cisco IOS XE)
от 17.1 до 17.5 включительно (Cisco IOS XE)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

Cisco Systems Inc. Cisco IOS XE 16.1
Cisco Systems Inc. Cisco IOS XE 16.2
Cisco Systems Inc. Cisco IOS XE 3.3XO
Cisco Systems Inc. Cisco IOS XE 3.7E
Cisco Systems Inc. Cisco IOS XE 3.9E
Cisco Systems Inc. Cisco IOS XE 3.15S
Cisco Systems Inc. Cisco IOS XE 3.16S
Cisco Systems Inc. Cisco IOS XE 3.17S
Cisco Systems Inc. Cisco IOS XE 16.11
Cisco Systems Inc. Cisco IOS XE 3.3SE
Cisco Systems Inc. Cisco IOS XE 3.5E
Cisco Systems Inc. Cisco IOS XE 3.6E
Cisco Systems Inc. Cisco IOS XE 3.14S
Cisco Systems Inc. Cisco IOS XE 3.18S
Cisco Systems Inc. Cisco IOS XE 3.18SP
Cisco Systems Inc. Cisco IOS XE 3.10E
Cisco Systems Inc. Cisco IOS 15.0EY
Cisco Systems Inc. Cisco IOS 15.0EX
Cisco Systems Inc. Cisco IOS 15.1SY
Cisco Systems Inc. Cisco IOS 15.4S
Cisco Systems Inc. Cisco IOS 15.2SY
Cisco Systems Inc. Cisco IOS 15.5S
Cisco Systems Inc. Cisco IOS 15.3SY
Cisco Systems Inc. Cisco IOS 15.6SP
Cisco Systems Inc. Cisco IOS 15.4SY
Cisco Systems Inc. Cisco IOS 15.5SY
Cisco Systems Inc. Cisco IOS 15.7M
Cisco Systems Inc. Cisco IOS 15.8M
Cisco Systems Inc. Cisco IOS 15.4T
Cisco Systems Inc. Cisco IOS 15.4M
Cisco Systems Inc. Cisco IOS 15.4CG
Cisco Systems Inc. Cisco IOS 15.5T
Cisco Systems Inc. Cisco IOS 15.4SN
Cisco Systems Inc. Cisco IOS 15.5M
Cisco Systems Inc. Cisco IOS 15.5SN
Cisco Systems Inc. Cisco IOS 15.6S
Cisco Systems Inc. Cisco IOS 15.6T
Cisco Systems Inc. Cisco IOS 15.5XB
Cisco Systems Inc. Cisco IOS 15.6SN
Cisco Systems Inc. Cisco IOS 15.3JD
Cisco Systems Inc. Cisco IOS 15.6M
Cisco Systems Inc. Cisco IOS 15.3JE
Cisco Systems Inc. Cisco IOS 15.3JF
Cisco Systems Inc. Cisco IOS 15.3JG
Cisco Systems Inc. Cisco IOS 15.3JH
Cisco Systems Inc. Cisco IOS 15.3JI
Cisco Systems Inc. Cisco IOS 15.3JJ
Cisco Systems Inc. Cisco IOS 15.2E
Cisco Systems Inc. Cisco IOS XE 16.12
Cisco Systems Inc. Cisco IOS 15.0SE
Cisco Systems Inc. Cisco IOS 15.0EZ
Cisco Systems Inc. Cisco IOS 15.2EY
Cisco Systems Inc. Cisco IOS 15.0EJ
Cisco Systems Inc. Cisco IOS 15.2EX
Cisco Systems Inc. Cisco IOS 15.0EK
Cisco Systems Inc. Cisco IOS 15.2EB
Cisco Systems Inc. Cisco IOS 15.2EA
Cisco Systems Inc. Cisco IOS 15.2EC
Cisco Systems Inc. Cisco IOS 12.2I
Cisco Systems Inc. Cisco IOS 15.9M
Cisco Systems Inc. Cisco IOS 15.3JPI
Cisco Systems Inc. Cisco IOS 15.1SVS
Cisco Systems Inc. Cisco IOS XE 3.11E
Cisco Systems Inc. Cisco IOS 15.3JPJ
Cisco Systems Inc. Cisco IOS 15.3JK
Cisco Systems Inc. Cisco IOS 15.1SVR
Cisco Systems Inc. Cisco IOS XE от 16.3 до 16.5 включительно
Cisco Systems Inc. Cisco IOS XE от 16.6 до 16.10 включительно
Cisco Systems Inc. Cisco IOS 15.1SVT
Cisco Systems Inc. Cisco IOS 15.3JPK
Cisco Systems Inc. Cisco IOS XE от 3.11S до 3.13S включительно
Cisco Systems Inc. Cisco IOS XE от 17.1 до 17.5 включительно

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.0 составляет 7,4)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-trustsec-dos-7fuXDR2

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 72%
0.00702
Низкий

7.7 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.7
nvd
больше 4 лет назад

A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run through the web UI. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 7.7
github
больше 3 лет назад

A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run through the web UI. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

EPSS

Процентиль: 72%
0.00702
Низкий

7.7 High

CVSS3

7.8 High

CVSS2