Multiple Cisco Products Root Shell Access Vulnerability

Related Vulnerabilities: CVE-2013-1125  

Multiple Cisco products contain a vulnerability that could allow a local attacker to gain shell access with root privileges. The vulnerability is due to incorrect validation of user-supplied input processed by the command-line interface (CLI) on Cisco products running the affected software. A local attacker with access to an affected device could exploit this vulnerability by submitting specially crafted input to be processed by the vulnerable component. Successful exploitation could allow an attacker to gain shell access with root privileges on a targeted system, which could result in a complete system compromise. Cisco has confirmed the vulnerability; however, software updates are not available. To exploit this vulnerability, the attacker must have local access to a targeted system. This access restriction limits the possibility of a successful exploit. Customers are advised to review the bug reports in the vendor announcements section for a current list of affected products and versions.