cisco-sa-20170317-cmp: Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
Published Mar 17, 2017
·Updated
Credit
This vulnerability was found during the analysis(documents related to the Vault 7 disclosure)
Affected Software
2 affected components
Cisco IOS
Cisco IOS XE
Event History
Mar 17, 2017
Advisory Published
04:00 PM
Data Sourced
04:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates exploitation can be performed over the network with low attack complexity. No prior privileges or user interaction are required.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8 (Critical).