Описание
A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.
Уязвимые конфигурации
Одно из
EPSS
6.7 Medium
CVSS3
6.7 Medium
CVSS3
7.2 High
CVSS2
Дефекты
Связанные уязвимости
A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on an affected device.
Уязвимость служб Virtual Services Container операционной системы Cisco IOS XE, позволяющая нарушителю повысить свои привилегии до уровня root
EPSS
6.7 Medium
CVSS3
6.7 Medium
CVSS3
7.2 High
CVSS2