CVE-2017-6719
MEDIUMCisco IOS XR Software - Command Injection
Title source: llmDescription
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.
Scores
CVSS v3
6.7
EPSS
0.0015
EPSS Percentile
35.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (3)
cisco/ios_xr
cisco/ios_xr
n/a/Cisco IOS XR
< Cisco IOS XR
Published
Jul 04, 2017
Tracked Since
Feb 18, 2026