6.9

CVE-2017-6606

A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Information: CSCuz06639 CSCuz42122. Known Affected Releases: 15.6(1.1)S 16.1.2 16.2.0 15.2(1)E. Known Fixed Releases: Denali-16.1.3 16.2(1.8) 16.1(2.61) 15.6(2)SP 15.6(2)S1 15.6(1)S2 15.5(3)S3a 15.5(3)S3 15.5(2)S4 15.5(1)S4 15.4(3)S6a 15.4(3)S6 15.3(3)S8a 15.3(3)S8 15.2(5)E 15.2(4)E3 15.2(3)E5 15.0(2)SQD3 15.0(1.9.2)SQD3 3.9(0)E.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version3.1.0s
CiscoIos Xe Version3.1.0sg
CiscoIos Xe Version3.1.1s
CiscoIos Xe Version3.1.1sg
CiscoIos Xe Version3.1.2s
CiscoIos Xe Version3.1.3s
CiscoIos Xe Version3.1.4as
CiscoIos Xe Version3.1.4s
CiscoIos Xe Version3.2.0se
CiscoIos Xe Version3.2.0sg
CiscoIos Xe Version3.2.0xo
CiscoIos Xe Version3.2.1s
CiscoIos Xe Version3.2.1se
CiscoIos Xe Version3.2.1sg
CiscoIos Xe Version3.2.1xo
CiscoIos Xe Version3.2.2s
CiscoIos Xe Version3.2.2se
CiscoIos Xe Version3.2.2sg
CiscoIos Xe Version3.2.3se
CiscoIos Xe Version3.2.3sg
CiscoIos Xe Version3.2.4sg
CiscoIos Xe Version3.2.5sg
CiscoIos Xe Version3.2.6sg
CiscoIos Xe Version3.2.7sg
CiscoIos Xe Version3.2.8sg
CiscoIos Xe Version3.2.9sg
CiscoIos Xe Version3.2.10sg
CiscoIos Xe Version3.2.11sg
CiscoIos Xe Version3.3.0s
CiscoIos Xe Version3.3.0se
CiscoIos Xe Version3.3.0sg
CiscoIos Xe Version3.3.0sq
CiscoIos Xe Version3.3.0xo
CiscoIos Xe Version3.3.1s
CiscoIos Xe Version3.3.1se
CiscoIos Xe Version3.3.1sg
CiscoIos Xe Version3.3.1sq
CiscoIos Xe Version3.3.1xo
CiscoIos Xe Version3.3.2s
CiscoIos Xe Version3.3.2se
CiscoIos Xe Version3.3.2sg
CiscoIos Xe Version3.3.2xo
CiscoIos Xe Version3.3.3se
CiscoIos Xe Version3.3.4se
CiscoIos Xe Version3.3.5se
CiscoIos Xe Version3.4.0as
CiscoIos Xe Version3.4.0s
CiscoIos Xe Version3.4.0sg
CiscoIos Xe Version3.4.0sq
CiscoIos Xe Version3.4.1s
CiscoIos Xe Version3.4.1sg
CiscoIos Xe Version3.4.1sq
CiscoIos Xe Version3.4.2s
CiscoIos Xe Version3.4.2sg
CiscoIos Xe Version3.4.3s
CiscoIos Xe Version3.4.3sg
CiscoIos Xe Version3.4.4s
CiscoIos Xe Version3.4.4sg
CiscoIos Xe Version3.4.5s
CiscoIos Xe Version3.4.5sg
CiscoIos Xe Version3.4.6s
CiscoIos Xe Version3.4.6sg
CiscoIos Xe Version3.4.7sg
CiscoIos Xe Version3.4.8sg
CiscoIos Xe Version3.5.0e
CiscoIos Xe Version3.5.0s
CiscoIos Xe Version3.5.0sq
CiscoIos Xe Version3.5.1e
CiscoIos Xe Version3.5.1s
CiscoIos Xe Version3.5.1sq
CiscoIos Xe Version3.5.2e
CiscoIos Xe Version3.5.2s
CiscoIos Xe Version3.5.2sq
CiscoIos Xe Version3.5.3e
CiscoIos Xe Version3.6.0e
CiscoIos Xe Version3.6.0s
CiscoIos Xe Version3.6.1e
CiscoIos Xe Version3.6.1s
CiscoIos Xe Version3.6.2ae
CiscoIos Xe Version3.6.2s
CiscoIos Xe Version3.6.3e
CiscoIos Xe Version3.6.4e
CiscoIos Xe Version3.6.5ae
CiscoIos Xe Version3.6.5e
CiscoIos Xe Version3.6.6e
CiscoIos Xe Version3.6.7e
CiscoIos Xe Version3.7.0bs
CiscoIos Xe Version3.7.0e
CiscoIos Xe Version3.7.0s
CiscoIos Xe Version3.7.1e
CiscoIos Xe Version3.7.1s
CiscoIos Xe Version3.7.2e
CiscoIos Xe Version3.7.2s
CiscoIos Xe Version3.7.2ts
CiscoIos Xe Version3.7.3e
CiscoIos Xe Version3.7.3s
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.4s
CiscoIos Xe Version3.7.5s
CiscoIos Xe Version3.7.6s
CiscoIos Xe Version3.7.7s
CiscoIos Xe Version3.8.0e
CiscoIos Xe Version3.8.0s
CiscoIos Xe Version3.8.1e
CiscoIos Xe Version3.8.1s
CiscoIos Xe Version3.8.2e
CiscoIos Xe Version3.8.2s
CiscoIos Xe Version3.9.0s
CiscoIos Xe Version3.9.1s
CiscoIos Xe Version3.9.2s
CiscoIos Xe Version3.10.0s
CiscoIos Xe Version3.10.1s
CiscoIos Xe Version3.10.1xbs
CiscoIos Xe Version3.10.2s
CiscoIos Xe Version3.10.2ts
CiscoIos Xe Version3.10.3s
CiscoIos Xe Version3.10.4s
CiscoIos Xe Version3.10.5s
CiscoIos Xe Version3.10.6s
CiscoIos Xe Version3.10.7s
CiscoIos Xe Version3.11.0s
CiscoIos Xe Version3.11.1s
CiscoIos Xe Version3.11.2s
CiscoIos Xe Version3.11.3s
CiscoIos Xe Version3.11.4s
CiscoIos Xe Version3.12.0as
CiscoIos Xe Version3.12.0s
CiscoIos Xe Version3.12.1s
CiscoIos Xe Version3.12.2s
CiscoIos Xe Version3.12.3s
CiscoIos Xe Version3.12.4s
CiscoIos Xe Version3.13.0as
CiscoIos Xe Version3.13.0s
CiscoIos Xe Version3.13.1s
CiscoIos Xe Version3.13.2as
CiscoIos Xe Version3.13.2s
CiscoIos Xe Version3.13.3s
CiscoIos Xe Version3.13.4s
CiscoIos Xe Version3.13.5as
CiscoIos Xe Version3.13.5s
CiscoIos Xe Version3.14.0s
CiscoIos Xe Version3.14.1s
CiscoIos Xe Version3.14.2s
CiscoIos Xe Version3.14.3s
CiscoIos Xe Version3.15.0s
CiscoIos Xe Version3.15.1cs
CiscoIos Xe Version3.15.1s
CiscoIos Xe Version3.15.2s
CiscoIos Xe Version3.15.3s
CiscoIos Xe Version3.16.0cs
CiscoIos Xe Version3.16.0s
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.1s
CiscoIos Xe Version3.16.2as
CiscoIos Xe Version3.16.2bs
CiscoIos Xe Version3.16.2s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1as
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.18.0as
CiscoIos Xe Version3.18.0s
CiscoIos Xe Version16.1.1
CiscoIos Xe Version16.1.2
CiscoIos Xe Version16.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.376
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 0.5 5.9
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.