Cisco IOS XE Software IOx Guest Shell Namespace Protection Vulnerability
CVE-2019-12670

6.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
25 September 2019

Badges

👾 Exploit Exists

Summary

A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficient file permissions. An attacker could exploit this vulnerability by modifying files that they should not have access to. A successful exploit could allow the attacker to remove container protections and perform file actions outside the namespace of the container.

Affected Version(s)

Cisco IOS XE Software 3.2.11aSG < unspecified

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.