Cisco Alert
3167Warning Date
Severity Level
Warning Number
Target Sector
2 February, 2023
● High
2023-5436
All
Cisco has released a security update to address a high vulnerability in Cisco IOx application hosting environment in the following products:
- Cisco devices that are running Cisco IOS XE Software if they have the Cisco IOx feature enabled and they do not support native docker.
- Cisco Products that do not support native docker, if they are running a vulnerable software release and have the Cisco IOx feature enabled:
- 800 Series Industrial ISRs
- Catalyst Access Points (COS-APs)
- CGR1000 Compute Modules
- IC3000 Industrial Compute Gateways (software releases earlier than 1.2.1)
- IR510 WPAN Industrial Routers
Remote authenticated attacker could execute arbitrary commands as root on the underlaying host operating system.
The CERT team encourages users to review Cisco security advisory and update the affected products:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-8whGn5dL