First published: Wed Sep 27 2023(Updated: )
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary Cisco IOS XE Software CLI commands with level 15 privileges. Note: This vulnerability is exploitable only if the attacker obtains the credentials for a Lobby Ambassador account. This account is not configured by default.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =16.12.4 | |
Cisco IOS XE | =16.12.4a | |
Cisco IOS XE | =16.12.5 | |
Cisco IOS XE | =16.12.5a | |
Cisco IOS XE | =16.12.5b | |
Cisco IOS XE | =16.12.6 | |
Cisco IOS XE | =16.12.6a | |
Cisco IOS XE | =16.12.7 | |
Cisco IOS XE | =16.12.8 | |
Cisco IOS XE | =16.12.9 | |
Cisco IOS XE | =17.2.2 | |
Cisco IOS XE | =17.2.3 | |
Cisco IOS XE | =17.3.1 | |
Cisco IOS XE | =17.3.1a | |
Cisco IOS XE | =17.3.1w | |
Cisco IOS XE | =17.3.1x | |
Cisco IOS XE | =17.3.1z | |
Cisco IOS XE | =17.3.2 | |
Cisco IOS XE | =17.3.3 | |
Cisco IOS XE | =17.3.4 | |
Cisco IOS XE | =17.3.4a | |
Cisco IOS XE | =17.3.4b | |
Cisco IOS XE | =17.3.4c | |
Cisco IOS XE | =17.3.5 | |
Cisco IOS XE | =17.3.5a | |
Cisco IOS XE | =17.3.5b | |
Cisco IOS XE | =17.3.6 | |
Cisco IOS XE | =17.4.1 | |
Cisco IOS XE | =17.4.1a | |
Cisco IOS XE | =17.4.1b | |
Cisco IOS XE | =17.4.2 | |
Cisco IOS XE | =17.4.2a | |
Cisco IOS XE | =17.5.1 | |
Cisco IOS XE | =17.5.1a | |
Cisco IOS XE | =17.5.1b | |
Cisco IOS XE | =17.5.1c | |
Cisco IOS XE | =17.6.1 | |
Cisco IOS XE | =17.6.1.z | |
Cisco IOS XE | =17.6.1a | |
Cisco IOS XE | =17.6.1w | |
Cisco IOS XE | =17.6.1x | |
Cisco IOS XE | =17.6.1y | |
Cisco IOS XE | =17.6.1z1 | |
Cisco IOS XE | =17.6.2 | |
Cisco IOS XE | =17.6.3 | |
Cisco IOS XE | =17.6.3a | |
Cisco IOS XE | =17.6.4 | |
Cisco IOS XE | =17.6.5 | |
Cisco IOS XE | =17.7.1 | |
Cisco IOS XE | =17.7.1a | |
Cisco IOS XE | =17.7.1b | |
Cisco IOS XE | =17.7.2 | |
Cisco IOS XE | =17.8.1 | |
Cisco IOS XE | =17.8.1a | |
Cisco IOS XE | =17.9.1 | |
Cisco IOS XE | =17.9.1a | |
Cisco IOS XE | =17.9.1w | |
Cisco IOS XE | =17.9.1x | |
Cisco IOS XE | =17.9.1x1 | |
Cisco IOS XE | =17.9.1y | |
Cisco IOS XE | =17.9.2 | |
Cisco IOS XE | =17.9.2a | |
Cisco IOS XE | =17.9.2b | |
Cisco IOS XE | =17.10.1 | |
Cisco IOS XE | =17.10.1a | |
Cisco IOS XE | =17.10.1b | |
Cisco IOS XE | =17.91w | |
Cisco Catalyst 9105ax | ||
Cisco Catalyst 9105axi | ||
Cisco Catalyst 9105axw | ||
Cisco Catalyst 9115ax | ||
Cisco Catalyst 9115axe | ||
Cisco Catalyst 9115axi | ||
Cisco Catalyst 9117ax | ||
Cisco Catalyst 9117axi | ||
Cisco Catalyst 9120ax | ||
Cisco Catalyst 9120axe | ||
Cisco Catalyst 9120axi | ||
Cisco Catalyst 9120axp | ||
Cisco Catalyst 9124ax | ||
Cisco Catalyst 9124axd | ||
Cisco Catalyst 9124axi | ||
Cisco Catalyst 9130ax | ||
Cisco Catalyst 9130axe | ||
Cisco Catalyst 9130axi | ||
Cisco Catalyst 9300 | ||
Cisco Catalyst 9300-24p-a | ||
Cisco Catalyst 9300-24p-e | ||
Cisco Catalyst 9300-24s-a | ||
Cisco Catalyst 9300-24s-e | ||
Cisco Catalyst 9300-24t-a | ||
Cisco Catalyst 9300-24t-e | ||
Cisco Catalyst 9300-24u-a | ||
Cisco Catalyst 9300-24u-e | ||
Cisco Catalyst 9300-24ux-a | ||
Cisco Catalyst 9300-24ux-e | ||
Cisco Catalyst 9300-48p-a | ||
Cisco Catalyst 9300-48p-e | ||
Cisco Catalyst 9300-48s-a | ||
Cisco Catalyst 9300-48s-e | ||
Cisco Catalyst 9300-48t-a | ||
Cisco Catalyst 9300-48t-e | ||
Cisco Catalyst 9300-48u-a | ||
Cisco Catalyst 9300-48u-e | ||
Cisco Catalyst 9300-48un-a | ||
Cisco Catalyst 9300-48un-e | ||
Cisco Catalyst 9300-48uxm-a | ||
Cisco Catalyst 9300-48uxm-e | ||
Cisco Catalyst 9300l | ||
Cisco Catalyst 9300l-24p-4g-a | ||
Cisco Catalyst 9300l-24p-4g-e | ||
Cisco Catalyst 9300l-24p-4x-a | ||
Cisco Catalyst 9300l-24p-4x-e | ||
Cisco Catalyst 9300l-24t-4g-a | ||
Cisco Catalyst 9300l-24t-4g-e | ||
Cisco Catalyst 9300l-24t-4x-a | ||
Cisco Catalyst 9300l-24t-4x-e | ||
Cisco Catalyst 9300l-48p-4g-a | ||
Cisco Catalyst 9300l-48p-4g-e | ||
Cisco Catalyst 9300l-48p-4x-a | ||
Cisco Catalyst 9300l-48p-4x-e | ||
Cisco Catalyst 9300l-48t-4g-a | ||
Cisco Catalyst 9300l-48t-4g-e | ||
Cisco Catalyst 9300l-48t-4x-a | ||
Cisco Catalyst 9300l-48t-4x-e | ||
Cisco Catalyst 9300l Stack | ||
Cisco Catalyst 9300lm | ||
Cisco Catalyst 9300x | ||
Cisco Catalyst 9400 | ||
Cisco Catalyst 9407r | ||
Cisco Catalyst 9410r | ||
Cisco Catalyst 9500 | ||
Cisco Catalyst 9500h | ||
Cisco Catalyst 9800 | ||
Cisco Catalyst 9800-40 | ||
Cisco Catalyst 9800-80 | ||
Cisco Catalyst 9800-cl | ||
Cisco Catalyst 9800-l | ||
Cisco Catalyst 9800-l-c | ||
Cisco Catalyst 9800-l-f | ||
All of | ||
Any of | ||
Cisco IOS XE | =16.12.4 | |
Cisco IOS XE | =16.12.4a | |
Cisco IOS XE | =16.12.5 | |
Cisco IOS XE | =16.12.5a | |
Cisco IOS XE | =16.12.5b | |
Cisco IOS XE | =16.12.6 | |
Cisco IOS XE | =16.12.6a | |
Cisco IOS XE | =16.12.7 | |
Cisco IOS XE | =16.12.8 | |
Cisco IOS XE | =16.12.9 | |
Cisco IOS XE | =17.2.2 | |
Cisco IOS XE | =17.2.3 | |
Cisco IOS XE | =17.3.1 | |
Cisco IOS XE | =17.3.1a | |
Cisco IOS XE | =17.3.1w | |
Cisco IOS XE | =17.3.1x | |
Cisco IOS XE | =17.3.1z | |
Cisco IOS XE | =17.3.2 | |
Cisco IOS XE | =17.3.3 | |
Cisco IOS XE | =17.3.4 | |
Cisco IOS XE | =17.3.4a | |
Cisco IOS XE | =17.3.4b | |
Cisco IOS XE | =17.3.4c | |
Cisco IOS XE | =17.3.5 | |
Cisco IOS XE | =17.3.5a | |
Cisco IOS XE | =17.3.5b | |
Cisco IOS XE | =17.3.6 | |
Cisco IOS XE | =17.4.1 | |
Cisco IOS XE | =17.4.1a | |
Cisco IOS XE | =17.4.1b | |
Cisco IOS XE | =17.4.2 | |
Cisco IOS XE | =17.4.2a | |
Cisco IOS XE | =17.5.1 | |
Cisco IOS XE | =17.5.1a | |
Cisco IOS XE | =17.5.1b | |
Cisco IOS XE | =17.5.1c | |
Cisco IOS XE | =17.6.1 | |
Cisco IOS XE | =17.6.1.z | |
Cisco IOS XE | =17.6.1a | |
Cisco IOS XE | =17.6.1w | |
Cisco IOS XE | =17.6.1x | |
Cisco IOS XE | =17.6.1y | |
Cisco IOS XE | =17.6.1z1 | |
Cisco IOS XE | =17.6.2 | |
Cisco IOS XE | =17.6.3 | |
Cisco IOS XE | =17.6.3a | |
Cisco IOS XE | =17.6.4 | |
Cisco IOS XE | =17.6.5 | |
Cisco IOS XE | =17.7.1 | |
Cisco IOS XE | =17.7.1a | |
Cisco IOS XE | =17.7.1b | |
Cisco IOS XE | =17.7.2 | |
Cisco IOS XE | =17.8.1 | |
Cisco IOS XE | =17.8.1a | |
Cisco IOS XE | =17.9.1 | |
Cisco IOS XE | =17.9.1a | |
Cisco IOS XE | =17.9.1w | |
Cisco IOS XE | =17.9.1x | |
Cisco IOS XE | =17.9.1x1 | |
Cisco IOS XE | =17.9.1y | |
Cisco IOS XE | =17.9.2 | |
Cisco IOS XE | =17.9.2a | |
Cisco IOS XE | =17.9.2b | |
Cisco IOS XE | =17.10.1 | |
Cisco IOS XE | =17.10.1a | |
Cisco IOS XE | =17.10.1b | |
Cisco IOS XE | =17.91w | |
Any of | ||
Cisco Catalyst 9105ax | ||
Cisco Catalyst 9105axi | ||
Cisco Catalyst 9105axw | ||
Cisco Catalyst 9115ax | ||
Cisco Catalyst 9115axe | ||
Cisco Catalyst 9115axi | ||
Cisco Catalyst 9117ax | ||
Cisco Catalyst 9117axi | ||
Cisco Catalyst 9120ax | ||
Cisco Catalyst 9120axe | ||
Cisco Catalyst 9120axi | ||
Cisco Catalyst 9120axp | ||
Cisco Catalyst 9124ax | ||
Cisco Catalyst 9124axd | ||
Cisco Catalyst 9124axi | ||
Cisco Catalyst 9130ax | ||
Cisco Catalyst 9130axe | ||
Cisco Catalyst 9130axi | ||
Cisco Catalyst 9300 | ||
Cisco Catalyst 9300-24p-a | ||
Cisco Catalyst 9300-24p-e | ||
Cisco Catalyst 9300-24s-a | ||
Cisco Catalyst 9300-24s-e | ||
Cisco Catalyst 9300-24t-a | ||
Cisco Catalyst 9300-24t-e | ||
Cisco Catalyst 9300-24u-a | ||
Cisco Catalyst 9300-24u-e | ||
Cisco Catalyst 9300-24ux-a | ||
Cisco Catalyst 9300-24ux-e | ||
Cisco Catalyst 9300-48p-a | ||
Cisco Catalyst 9300-48p-e | ||
Cisco Catalyst 9300-48s-a | ||
Cisco Catalyst 9300-48s-e | ||
Cisco Catalyst 9300-48t-a | ||
Cisco Catalyst 9300-48t-e | ||
Cisco Catalyst 9300-48u-a | ||
Cisco Catalyst 9300-48u-e | ||
Cisco Catalyst 9300-48un-a | ||
Cisco Catalyst 9300-48un-e | ||
Cisco Catalyst 9300-48uxm-a | ||
Cisco Catalyst 9300-48uxm-e | ||
Cisco Catalyst 9300l | ||
Cisco Catalyst 9300l-24p-4g-a | ||
Cisco Catalyst 9300l-24p-4g-e | ||
Cisco Catalyst 9300l-24p-4x-a | ||
Cisco Catalyst 9300l-24p-4x-e | ||
Cisco Catalyst 9300l-24t-4g-a | ||
Cisco Catalyst 9300l-24t-4g-e | ||
Cisco Catalyst 9300l-24t-4x-a | ||
Cisco Catalyst 9300l-24t-4x-e | ||
Cisco Catalyst 9300l-48p-4g-a | ||
Cisco Catalyst 9300l-48p-4g-e | ||
Cisco Catalyst 9300l-48p-4x-a | ||
Cisco Catalyst 9300l-48p-4x-e | ||
Cisco Catalyst 9300l-48t-4g-a | ||
Cisco Catalyst 9300l-48t-4g-e | ||
Cisco Catalyst 9300l-48t-4x-a | ||
Cisco Catalyst 9300l-48t-4x-e | ||
Cisco Catalyst 9300l Stack | ||
Cisco Catalyst 9300lm | ||
Cisco Catalyst 9300x | ||
Cisco Catalyst 9400 | ||
Cisco Catalyst 9407r | ||
Cisco Catalyst 9410r | ||
Cisco Catalyst 9500 | ||
Cisco Catalyst 9500h | ||
Cisco Catalyst 9800 | ||
Cisco Catalyst 9800-40 | ||
Cisco Catalyst 9800-80 | ||
Cisco Catalyst 9800-cl | ||
Cisco Catalyst 9800-l | ||
Cisco Catalyst 9800-l-c | ||
Cisco Catalyst 9800-l-f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.