cisco-sa-confd-priv-esc-LsGtCRx4: ConfD CLI Secure Shell Server Privilege Escalation Vulnerability
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a valid account on the affected
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for ConfD CLI Secure Shell Server Privilege Escalation?
The vulnerability ID for ConfD CLI Secure Shell Server Privilege Escalation is cisco-sa-confd-priv-esc-LsGtCRx4.
What is the severity level of the ConfD CLI Secure Shell Server Privilege Escalation vulnerability?
The severity level of the ConfD CLI Secure Shell Server Privilege Escalation vulnerability is high.
How can an attacker exploit the ConfD CLI Secure Shell Server Privilege Escalation vulnerability?
An attacker can exploit the ConfD CLI Secure Shell Server Privilege Escalation vulnerability by executing arbitrary commands at the level of the account under which ConfD is running.
Who is affected by the ConfD CLI Secure Shell Server Privilege Escalation vulnerability?
Any user with a valid account on the affected device is affected by the ConfD CLI Secure Shell Server Privilege Escalation vulnerability.
What is the recommended action to mitigate the ConfD CLI Secure Shell Server Privilege Escalation vulnerability?
To mitigate the ConfD CLI Secure Shell Server Privilege Escalation vulnerability, users should upgrade to one of the recommended software versions provided by Cisco.