PT-2013-2897 · Cisco · Quad+9

Publicado

2013-02-19

·

Atualizado

2013-02-20

·

CVE-2013-1125

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine Software (affected versions not specified) Cisco Secure Access Control System (ACS) (affected versions not specified) Cisco Application Networking Manager (ANM) (affected versions not specified) Cisco Prime LAN Management Solution (LMS) (affected versions not specified) Cisco Prime Network Control System (affected versions not specified) Cisco Quad (affected versions not specified) Cisco Context Directory Agent (affected versions not specified) Cisco Prime Collaboration (affected versions not specified) Cisco Unified Provisioning Manager (affected versions not specified) Cisco Network Services Manager (affected versions not specified)
Description The command-line interface in various Cisco software products does not properly validate input, allowing local users to obtain root privileges.
Recommendations For Cisco Identity Services Engine Software, update to a version that properly validates input in the command-line interface. For Cisco Secure Access Control System (ACS), update to a version that properly validates input in the command-line interface. For Cisco Application Networking Manager (ANM), update to a version that properly validates input in the command-line interface. For Cisco Prime LAN Management Solution (LMS), update to a version that properly validates input in the command-line interface. For Cisco Prime Network Control System, update to a version that properly validates input in the command-line interface. For Cisco Quad, update to a version that properly validates input in the command-line interface. For Cisco Context Directory Agent, update to a version that properly validates input in the command-line interface. For Cisco Prime Collaboration, update to a version that properly validates input in the command-line interface. For Cisco Unified Provisioning Manager, update to a version that properly validates input in the command-line interface. For Cisco Network Services Manager, update to a version that properly validates input in the command-line interface.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1125

Produtos afetados

Cisco Application Networking Manager
Context Directory Agent
Identity Services Engine
Network Services Manager
Prime Collaboration
Prime Lan Management Solution
Cisco Prime Network Control System
Quad
Secure Access Control System
Unified Provisioning Manager