cisco-sa-iosxr-shellutil-HCb278wD: Cisco IOS XR Software CLI Arbitrary File Read Vulnerability
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device.This vulnerability is due to incorrect
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-iosxr-shellutil-HCb278wD?
The severity of cisco-sa-iosxr-shellutil-HCb278wD is considered high due to the potential for authenticated local attackers to read sensitive files.
How do I fix cisco-sa-iosxr-shellutil-HCb278wD?
To fix cisco-sa-iosxr-shellutil-HCb278wD, update to the latest version of Cisco IOS XR Software that addresses this vulnerability.
What types of devices are affected by cisco-sa-iosxr-shellutil-HCb278wD?
Devices running affected versions of Cisco IOS XR Software, specifically the Cisco IOS XRv 9000, are susceptible to cisco-sa-iosxr-shellutil-HCb278wD.
What attack vector is associated with cisco-sa-iosxr-shellutil-HCb278wD?
The attack vector associated with cisco-sa-iosxr-shellutil-HCb278wD involves authenticated local access to the device.
What is the impact of cisco-sa-iosxr-shellutil-HCb278wD?
The impact of cisco-sa-iosxr-shellutil-HCb278wD is that it allows an authenticated attacker to read any file in the underlying Linux file system.