cisco-sa-ios-xe-cmd-inject-rPJM8BGL: Cisco IOS XE Software HTTP API Command Injection Vulnerability
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system.This vulnerability is due to insufficient input validation. An attacker with
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ios-xe-cmd-inject-rPJM8BGL?
The severity of cisco-sa-ios-xe-cmd-inject-rPJM8BGL is critical due to the potential for remote command injection with root privileges.
How do I fix cisco-sa-ios-xe-cmd-inject-rPJM8BGL?
To fix cisco-sa-ios-xe-cmd-inject-rPJM8BGL, upgrade to the latest patched version of Cisco IOS XE Software as recommended in the advisory.
What causes the vulnerability cisco-sa-ios-xe-cmd-inject-rPJM8BGL?
cisco-sa-ios-xe-cmd-inject-rPJM8BGL is caused by insufficient input validation in the HTTP API subsystem.
Who is affected by cisco-sa-ios-xe-cmd-inject-rPJM8BGL?
Devices running vulnerable versions of Cisco IOS XE Software are affected by cisco-sa-ios-xe-cmd-inject-rPJM8BGL.
Is there a workaround for cisco-sa-ios-xe-cmd-inject-rPJM8BGL?
There are currently no known workarounds for cisco-sa-ios-xe-cmd-inject-rPJM8BGL; upgrading is the recommended action.