PT-2014-3774 · Cisco · Cisco Prime Infrastructure
Publicado
2014-02-27
·
Atualizado
2019-07-29
·
CVE-2014-0679
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Infrastructure versions 1.2 through 1.3 before 1.3.0.20-2
Cisco Prime Infrastructure versions 1.4 before 1.4.0.45-2
Cisco Prime Infrastructure versions 2.0 before 2.0.0.0.294-2
Description
The issue allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL.
Recommendations
For versions 1.2 through 1.3 before 1.3.0.20-2, update to version 1.3.0.20-2 or later.
For versions 1.4 before 1.4.0.45-2, update to version 1.4.0.45-2 or later.
For versions 2.0 before 2.0.0.0.294-2, update to version 2.0.0.0.294-2 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Prime Infrastructure