Command Injection Vulnerability in Cisco ASR 5000 Series Routers
CVE-2018-0217
6.7MEDIUM
What is CVE-2018-0217?
A command injection vulnerability exists in the Command Line Interface (CLI) of Cisco StarOS for ASR 5000 Series Routers. This issue arises from insufficient validation of user-supplied commands in the CLI, which could be exploited by an authenticated local attacker. By injecting malicious arguments into CLI commands, the attacker could execute arbitrary commands within the context of the system. Successful exploitation requires valid administrator credentials, making it crucial for organizations to implement stringent access controls and monitoring on their systems.
Affected Version(s)
Cisco StarOS Cisco StarOS