Vulnerability Bulletins |
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability |
|
| Affected software | Cisco |
|
A privilege escalation vulnerability in the SSH subsystem in Cisco ASR 5000 Series devices running StarOS could allow an authenticated, remote attacker to elevate privileges. The attacker would need to have a valid and configured SSH authorized key and access to the same device from which the privileged administrator connects. The vulnerability is due to an error that occurs when multiple users are configured to use SSH keys as the authentication mechanism. Administrative accounts configured in More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160218-asr?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20ASR%205000%20Series%20StarOS%20SSH%20Subsystem%20Privilege%20Escalatio |
|






