CVE-2018-0477 is a command injection vulnerability in the CLI parser of Cisco IOS XE Software. An authenticated, local attacker with privileged EXEC mode access can exploit improper command argument sanitization to execute arbitrary commands with root privileges on the underlying Linux shell. This vulnerability has a CVSS score of 6.7 (Medium) due to its local attack vector and high impact on confidentiality, integrity, and availability. While there are no known public exploits or Metasploit modules, the vulnerability has received some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.3\(3\)s3.16CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.3\(3\)s3.16:*:*:*:*:*:*:* | ||
16.7\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7\(1\):*:*:*:*:*:*:* | ||
16.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.