CVE-2017-6707

A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the StarOS CLI of an affected system and execute arbitrary shell commands as a Linux root user on the system, aka Command Injection. The vulnerability exists because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this vulnerability by submitting a crafted CLI command for execution in a Linux shell command as a root user. Cisco Bug IDs: CSCvc69329, CSCvc72930.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
ciscostaros
11.0_base:_base
ciscostaros
12.0.0
ciscostaros
12.1_base:_base
ciscostaros
12.2\(300\)
ciscostaros
12.2_base:_base
ciscostaros
14.0\(600\)
ciscostaros
14.0.0
ciscostaros
15.0\(912\)
ciscostaros
15.0\(935\)
ciscostaros
15.0\(938\)
ciscostaros
15.0_base:_base
ciscostaros
16.0\(900\)
ciscostaros
16.0.0
ciscostaros
16.1.0
ciscostaros
16.1.1
ciscostaros
16.1.2
ciscostaros
16.5.0
ciscostaros
16.5.2
ciscostaros
17.2.0
ciscostaros
17.2.0.59184
ciscostaros
17.3.0
ciscostaros
17.3.1
ciscostaros
17.3_base:_base
ciscostaros
17.7.0
ciscostaros
18.0.0
ciscostaros
18.0.0.57828
ciscostaros
18.0.0.59167
ciscostaros
18.0.0.59211
ciscostaros
18.0.l0.59219:l0.59219
ciscostaros
18.1.0
ciscostaros
18.1.0.59776
ciscostaros
18.1.0.59780
ciscostaros
18.1_base:_base
ciscostaros
18.3.0
ciscostaros
18.3_base:_base
ciscostaros
18.4.0
ciscostaros
19.0.1
ciscostaros
19.0.m0.60737:m0.60737
ciscostaros
19.0.m0.60828:m0.60828
ciscostaros
19.0.m0.61045:m0.61045
ciscostaros
19.1.0
ciscostaros
19.1.0.61559
ciscostaros
19.2.0
ciscostaros
19.3.0
ciscostaros
20.0.0
ciscostaros
20.0.1.0
ciscostaros
20.0.1.a0:a0
ciscostaros
20.0.1.v0:v0
ciscostaros
20.0.2.3
ciscostaros
20.0.2.3.65026
ciscostaros
20.0.2.v1:v1
ciscostaros
20.0.m0.62842:m0.62842
ciscostaros
20.0.m0.63229:m0.63229
ciscostaros
20.0.v0:v0
ciscostaros
21.0.0
ciscostaros
21.0_base:_base
ciscostaros
21.0_m0.64246:_m0.64246
ciscostaros
21.0_m0.64702:_m0.64702
𝑥
= Vulnerable software versions