First published: Fri Nov 07 2014(Updated: )
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | <=3.5e | |
Cisco AIR-CT5760 | ||
Cisco Catalyst 3850 | ||
Cisco Catalyst 3860 Series Switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7990 is considered a critical vulnerability, as it allows local users to gain Linux root access on affected Cisco devices.
To mitigate CVE-2014-7990, upgrade affected Cisco IOS XE devices to a version later than 3.5E.
CVE-2014-7990 impacts Cisco IOS XE 3.5E and earlier versions on WS-C3850, WS-C3860, and AIR-CT5760 devices.
Yes, CVE-2014-7990 can be exploited by local users with administrative privileges to gain unauthorized root access.
The best approach for CVE-2014-7990 is to apply the necessary software updates, as no practical workaround is available.