Cisco StarOS for ASR 5000 Series Routers Command-Line Interface Security Bypass Vulnerability
The vulnerability is due to insufficient input sanitization of user-supplied input at the CLI. An attacker could exploit this vulnerability by crafting a script on the device that will allow them to bypass built-in restrictions. An exploit could allow the unauthorized user to launch the CLI directly from a command shell.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2vJ8st6
The vulnerability is due to insufficient input sanitization of user-supplied input at the CLI. An attacker could exploit this vulnerability by crafting a script on the device that will allow them to bypass built-in restrictions. An exploit could allow the unauthorized user to launch the CLI directly from a command shell.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2vJ8st6
Security Impact Rating: Medium
CVE: CVE-2017-6773
from Cisco Security Advisory http://ift.tt/2vJ8st6