Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Physical
0

CVE-2017-6606

Disclosure Date: April 07, 2017
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Information: CSCuz06639 CSCuz42122. Known Affected Releases: 15.6(1.1)S 16.1.2 16.2.0 15.2(1)E. Known Fixed Releases: Denali-16.1.3 16.2(1.8) 16.1(2.61) 15.6(2)SP 15.6(2)S1 15.6(1)S2 15.5(3)S3a 15.5(3)S3 15.5(2)S4 15.5(1)S4 15.4(3)S6a 15.4(3)S6 15.3(3)S8a 15.3(3)S8 15.2(5)E 15.2(4)E3 15.2(3)E5 15.0(2)SQD3 15.0(1.9.2)SQD3 3.9(0)E.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.4 Medium
Impact Score:
5.9
Exploitability Score:
0.5
Vector:
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Physical
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • cisco

Products

  • ios xe 16.1.1,
  • ios xe 16.1.2,
  • ios xe 16.2.1,
  • ios xe 3.1.0s,
  • ios xe 3.1.0sg,
  • ios xe 3.1.1s,
  • ios xe 3.1.1sg,
  • ios xe 3.1.2s,
  • ios xe 3.1.3s,
  • ios xe 3.1.4as,
  • ios xe 3.1.4s,
  • ios xe 3.10.0s,
  • ios xe 3.10.1s,
  • ios xe 3.10.1xbs,
  • ios xe 3.10.2s,
  • ios xe 3.10.2ts,
  • ios xe 3.10.3s,
  • ios xe 3.10.4s,
  • ios xe 3.10.5s,
  • ios xe 3.10.6s,
  • ios xe 3.10.7s,
  • ios xe 3.11.0s,
  • ios xe 3.11.1s,
  • ios xe 3.11.2s,
  • ios xe 3.11.3s,
  • ios xe 3.11.4s,
  • ios xe 3.12.0as,
  • ios xe 3.12.0s,
  • ios xe 3.12.1s,
  • ios xe 3.12.2s,
  • ios xe 3.12.3s,
  • ios xe 3.12.4s,
  • ios xe 3.13.0as,
  • ios xe 3.13.0s,
  • ios xe 3.13.1s,
  • ios xe 3.13.2as,
  • ios xe 3.13.2s,
  • ios xe 3.13.3s,
  • ios xe 3.13.4s,
  • ios xe 3.13.5as,
  • ios xe 3.13.5s,
  • ios xe 3.14.0s,
  • ios xe 3.14.1s,
  • ios xe 3.14.2s,
  • ios xe 3.14.3s,
  • ios xe 3.15.0s,
  • ios xe 3.15.1cs,
  • ios xe 3.15.1s,
  • ios xe 3.15.2s,
  • ios xe 3.15.3s,
  • ios xe 3.16.0cs,
  • ios xe 3.16.0s,
  • ios xe 3.16.1as,
  • ios xe 3.16.1s,
  • ios xe 3.16.2as,
  • ios xe 3.16.2bs,
  • ios xe 3.16.2s,
  • ios xe 3.17.0s,
  • ios xe 3.17.1as,
  • ios xe 3.17.1s,
  • ios xe 3.18.0as,
  • ios xe 3.18.0s,
  • ios xe 3.2.0se,
  • ios xe 3.2.0sg,
  • ios xe 3.2.0xo,
  • ios xe 3.2.10sg,
  • ios xe 3.2.11sg,
  • ios xe 3.2.1s,
  • ios xe 3.2.1se,
  • ios xe 3.2.1sg,
  • ios xe 3.2.1xo,
  • ios xe 3.2.2s,
  • ios xe 3.2.2se,
  • ios xe 3.2.2sg,
  • ios xe 3.2.3se,
  • ios xe 3.2.3sg,
  • ios xe 3.2.4sg,
  • ios xe 3.2.5sg,
  • ios xe 3.2.6sg,
  • ios xe 3.2.7sg,
  • ios xe 3.2.8sg,
  • ios xe 3.2.9sg,
  • ios xe 3.3.0s,
  • ios xe 3.3.0se,
  • ios xe 3.3.0sg,
  • ios xe 3.3.0sq,
  • ios xe 3.3.0xo,
  • ios xe 3.3.1s,
  • ios xe 3.3.1se,
  • ios xe 3.3.1sg,
  • ios xe 3.3.1sq,
  • ios xe 3.3.1xo,
  • ios xe 3.3.2s,
  • ios xe 3.3.2se,
  • ios xe 3.3.2sg,
  • ios xe 3.3.2xo,
  • ios xe 3.3.3se,
  • ios xe 3.3.4se,
  • ios xe 3.3.5se,
  • ios xe 3.4.0as,
  • ios xe 3.4.0s,
  • ios xe 3.4.0sg,
  • ios xe 3.4.0sq,
  • ios xe 3.4.1s,
  • ios xe 3.4.1sg,
  • ios xe 3.4.1sq,
  • ios xe 3.4.2s,
  • ios xe 3.4.2sg,
  • ios xe 3.4.3s,
  • ios xe 3.4.3sg,
  • ios xe 3.4.4s,
  • ios xe 3.4.4sg,
  • ios xe 3.4.5s,
  • ios xe 3.4.5sg,
  • ios xe 3.4.6s,
  • ios xe 3.4.6sg,
  • ios xe 3.4.7sg,
  • ios xe 3.4.8sg,
  • ios xe 3.5.0e,
  • ios xe 3.5.0s,
  • ios xe 3.5.0sq,
  • ios xe 3.5.1e,
  • ios xe 3.5.1s,
  • ios xe 3.5.1sq,
  • ios xe 3.5.2e,
  • ios xe 3.5.2s,
  • ios xe 3.5.2sq,
  • ios xe 3.5.3e,
  • ios xe 3.6.0e,
  • ios xe 3.6.0s,
  • ios xe 3.6.1e,
  • ios xe 3.6.1s,
  • ios xe 3.6.2ae,
  • ios xe 3.6.2s,
  • ios xe 3.6.3e,
  • ios xe 3.6.4e,
  • ios xe 3.6.5ae,
  • ios xe 3.6.5e,
  • ios xe 3.6.6e,
  • ios xe 3.6.7e,
  • ios xe 3.7.0bs,
  • ios xe 3.7.0e,
  • ios xe 3.7.0s,
  • ios xe 3.7.1e,
  • ios xe 3.7.1s,
  • ios xe 3.7.2e,
  • ios xe 3.7.2s,
  • ios xe 3.7.2ts,
  • ios xe 3.7.3e,
  • ios xe 3.7.3s,
  • ios xe 3.7.4e,
  • ios xe 3.7.4s,
  • ios xe 3.7.5s,
  • ios xe 3.7.6s,
  • ios xe 3.7.7s,
  • ios xe 3.8.0e,
  • ios xe 3.8.0s,
  • ios xe 3.8.1e,
  • ios xe 3.8.1s,
  • ios xe 3.8.2e,
  • ios xe 3.8.2s,
  • ios xe 3.9.0s,
  • ios xe 3.9.1s,
  • ios xe 3.9.2s

Additional Info

Technical Analysis