Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3pw-jcpx-2qcc

Опубликовано: 27 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A successful exploit could allow the attacker to elevate privileges from Administrator to root.

A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A successful exploit could allow the attacker to elevate privileges from Administrator to root.

EPSS

Процентиль: 33%
0.00128
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-184

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A successful exploit could allow the attacker to elevate privileges from Administrator to root.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость реализации протокола NETCONF операционных систем Cisco IOS XE, позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 33%
0.00128
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-184