cisco-sa-20170621-ios: Cisco IOS XR Software Local Command Injection Vulnerability
Published Jun 21, 2017
·Updated
Affected Software
1 affected component
Cisco IOS XR Software
Event History
Jun 21, 2017
Advisory Published
04:00 PM
Data Sourced
04:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and high privileges are required. No user interaction is required.
2
What could be affected if the vulnerability is exploited?
The CVSS assessment rates confidentiality, integrity, and availability impact as high. The scope is unchanged.