CVE-2017-3819 is a privilege escalation vulnerability in the Secure Shell (SSH) subsystem of Cisco ASR 5000/5500/5700 Series devices and Cisco Virtualized Packet Core running StarOS. It allows an authenticated, remote attacker to gain unrestricted root shell access due to missing input validation during SSH or SFTP login. The vulnerability has a CVSSv3 score of 8.8 (High), indicating a significant risk. An attacker with valid credentials can exploit this remotely over an established TCP connection to port 22, requiring low attack complexity and resulting in full confidentiality, integrity, and availability compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability. Despite its high severity, it appears to have received limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:18.0.0:*:*:*:*:*:*:* | ||
18.0.0.57828CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:18.0.0.57828:*:*:*:*:*:*:* | ||
18.0.0.59167CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:18.0.0.59167:*:*:*:*:*:*:* | ||
18.0.0.59211CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:18.0.0.59211:*:*:*:*:*:*:* | ||
18.0.l0.59219CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:18.0.l0.59219:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.