CLI Security Bypass in Cisco ASR 5000 Series Routers
CVE-2017-6773
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 17 August 2017
What is CVE-2017-6773?
A vulnerability located within the Command-Line Interface (CLI) of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system allows an authenticated, local attacker to bypass existing CLI restrictions. This vulnerability arises from inadequate input sanitization of user-supplied inputs within the CLI. By crafting specific scripts, an attacker could exploit this weakness, gaining unauthorized access to execute commands directly at the underlying operating system level. The ability to launch the CLI from a command shell can have significant security implications, making it crucial for users to assess their devices for potential exploits. Relevant Cisco Bug IDs include CSCvd47722.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
StarOS for ASR 5000 Series Aggregated Services Routers 21.0.v0.65839
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved