File Modification Vulnerability in Cisco IOx Application Framework
CVE-2017-3852
8.1HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 22 March 2017
Summary
A vulnerability in the application-hosting framework of Cisco IOx can be exploited by an authenticated remote attacker to write or modify arbitrary files within the virtual instance on the affected device. This issue arises from inadequate input validation of user-supplied application packages. By uploading a malicious package, an attacker can manipulate files, although the impact is confined to the virtual instance without affecting the host router. The vulnerability is present in Cisco IOx Releases 1.0.0.0 and 1.1.0.0. For detailed information, refer to the Cisco security advisory.
Affected Version(s)
Cisco Application-Hosting Framework Cisco Application-Hosting Framework
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved