First published: Fri Nov 07 2014(Updated: )
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | <=3.5e | |
Cisco Air-ct5760 | ||
Cisco Ws-c3850 | ||
Cisco Ws-c3860 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.