PT-2014-3774 · Cisco · Cisco Prime Infrastructure

Publicado

2014-02-27

·

Atualizado

2019-07-29

·

CVE-2014-0679

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure versions 1.2 through 1.3 before 1.3.0.20-2 Cisco Prime Infrastructure versions 1.4 before 1.4.0.45-2 Cisco Prime Infrastructure versions 2.0 before 2.0.0.0.294-2
Description The issue allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL.
Recommendations For versions 1.2 through 1.3 before 1.3.0.20-2, update to version 1.3.0.20-2 or later. For versions 1.4 before 1.4.0.45-2, update to version 1.4.0.45-2 or later. For versions 2.0 before 2.0.0.0.294-2, update to version 2.0.0.0.294-2 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0679

Produtos afetados

Cisco Prime Infrastructure