Command Injection Vulnerability in Cisco StarOS for ASR and 5500 Series
CVE-2017-6707
8.2HIGH
What is CVE-2017-6707?
A vulnerability exists within the CLI command-parsing functionality of the Cisco StarOS operating system that enables an authenticated local attacker to execute arbitrary shell commands with root privileges. This occurs due to inadequate sanitization of commands before they are executed in a Linux shell environment. By supplying specially crafted CLI commands, attackers can bypass security measures, gaining control over the system and potentially compromising sensitive data. It is crucial for affected users to apply recommended updates and patches to mitigate this vulnerability.
Affected Version(s)
Cisco StarOS Cisco StarOS