CVE-2017-6719

MEDIUM

Cisco IOS XR Software - Command Injection

Title source: llm

Description

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.

Scores

CVSS v3 6.7
EPSS 0.0015
EPSS Percentile 35.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
cisco/ios_xr
cisco/ios_xr
n/a/Cisco IOS XR < Cisco IOS XR
Published Jul 04, 2017
Tracked Since Feb 18, 2026