File Modification Vulnerability in Cisco IOx Application Framework
CVE-2017-3852
8.1HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 22 March 2017
What is CVE-2017-3852?
A vulnerability in the application-hosting framework of Cisco IOx can be exploited by an authenticated remote attacker to write or modify arbitrary files within the virtual instance on the affected device. This issue arises from inadequate input validation of user-supplied application packages. By uploading a malicious package, an attacker can manipulate files, although the impact is confined to the virtual instance without affecting the host router. The vulnerability is present in Cisco IOx Releases 1.0.0.0 and 1.1.0.0. For detailed information, refer to the Cisco security advisory.
Affected Version(s)
Cisco Application-Hosting Framework Cisco Application-Hosting Framework