Privilege Escalation Vulnerability in Cisco ASR 5000 Series Routers
CVE-2017-6775
5.7MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 17 August 2017
Summary
A vulnerability exists in the command-line interface of Cisco ASR 5000 Series Aggregated Services Routers running the StarOS operating system. This issue arises from improper permissions being assigned to certain user roles, allowing an authenticated local attacker to elevate privileges to an admin level. By exploiting this vulnerability, an attacker can log into the device via the shell and modify environment variables to gain complete control over the affected device.
Affected Version(s)
StarOS for ASR 5000 Series Aggregated Services Routers 21.0.v0.65839
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved