Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-328f-6h62-x2vm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device. An attacker could exploit this vulnerability by connecting to an affected device's guest shell, and accessing or modifying restricted files. A successful exploit could allow the attacker to view or modify restricted information or configurations that are normally not accessible to system administrators.

A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device. An attacker could exploit this vulnerability by connecting to an affected device's guest shell, and accessing or modifying restricted files. A successful exploit could allow the attacker to view or modify restricted information or configurations that are normally not accessible to system administrators.

EPSS

Процентиль: 33%
0.0013
Низкий

6 Medium

CVSS3

Дефекты

CWE-284
CWE-732

Связанные уязвимости

CVSS3: 6
nvd
больше 5 лет назад

A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device. An attacker could exploit this vulnerability by connecting to an affected device's guest shell, and accessing or modifying restricted files. A successful exploit could allow the attacker to view or modify restricted information or configurations that are normally not accessible to system administrators.

CVSS3: 6
fstec
больше 5 лет назад

Уязвимость гостевой оболочки операционной системы Cisco IOS XE, позволяющая нарушителю получить доступ для чтения и записи к системным и конфигурационным файлам

EPSS

Процентиль: 33%
0.0013
Низкий

6 Medium

CVSS3

Дефекты

CWE-284
CWE-732