CVE-2016-6414: OS Command Injection
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6414?
CVE-2016-6414 is classified as a high-severity vulnerability due to its potential to allow local users to execute arbitrary commands on the guest OS.
How do I fix CVE-2016-6414?
To mitigate CVE-2016-6414, upgrade to a fixed version of Cisco IOS or IOS XE that addresses this vulnerability.
Who is affected by CVE-2016-6414?
Local users of Cisco IOS version 15.6 and earlier and IOS XE version 3.18 and earlier are affected by CVE-2016-6414.
What type of vulnerability is CVE-2016-6414?
CVE-2016-6414 is a command injection vulnerability that allows execution of arbitrary IOx commands.
What is the impact of CVE-2016-6414?
The impact of CVE-2016-6414 includes unauthorized access to the guest OS, leading to potential data breaches or system compromise.