First published: Thu Sep 22 2016(Updated: )
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.6\(1\)t1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6414 is classified as a high-severity vulnerability due to its potential to allow local users to execute arbitrary commands on the guest OS.
To mitigate CVE-2016-6414, upgrade to a fixed version of Cisco IOS or IOS XE that addresses this vulnerability.
Local users of Cisco IOS version 15.6 and earlier and IOS XE version 3.18 and earlier are affected by CVE-2016-6414.
CVE-2016-6414 is a command injection vulnerability that allows execution of arbitrary IOx commands.
The impact of CVE-2016-6414 includes unauthorized access to the guest OS, leading to potential data breaches or system compromise.