Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6c4-897q-gvcg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.

A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.

EPSS

Процентиль: 18%
0.00059
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.7
nvd
больше 5 лет назад

A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.

CVSS3: 6.7
fstec
больше 5 лет назад

Уязвимость служб Virtual Services Container операционной системы Cisco IOS XE, позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 18%
0.00059
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-20