cisco-sa-nso-priv-esc-XXqRtTfT: Cisco Network Services Orchestrator CLI Secure Shell Server Privilege Escalation Vulnerability
A vulnerability in Cisco Network Services Orchestrator (NSO) could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which Cisco NSO is running, which is root by default. To exploit this vulnerability, an attacker must have a valid
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-nso-priv-esc-XXqRtTfT?
The severity of cisco-sa-nso-priv-esc-XXqRtTfT is high, as it allows authenticated local attackers to execute arbitrary commands.
How do I fix cisco-sa-nso-priv-esc-XXqRtTfT?
To fix cisco-sa-nso-priv-esc-XXqRtTfT, update your Cisco NSO to one of the fixed versions, which include 5.8.11, 5.7.13, or 5.6.14.1.
Who is affected by cisco-sa-nso-priv-esc-XXqRtTfT?
Cisco NSO users running versions prior to 5.8.11, 5.7.13, or 5.6.14.1 are affected by cisco-sa-nso-priv-esc-XXqRtTfT.
What type of attacker can exploit cisco-sa-nso-priv-esc-XXqRtTfT?
An authenticated local attacker can exploit the cisco-sa-nso-priv-esc-XXqRtTfT vulnerability to execute commands with root privileges.
What product is impacted by cisco-sa-nso-priv-esc-XXqRtTfT?
Cisco Network Services Orchestrator (NSO) is the product impacted by the cisco-sa-nso-priv-esc-XXqRtTfT vulnerability.