PT-2015-3189 · Cisco · Cisco Wireless Lan Controller+1

Publicado

2015-06-25

·

Atualizado

2016-12-28

·

CVE-2015-4224

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller versions 7.0(240.0)
Description The issue allows local users to execute arbitrary OS commands in a privileged context via crafted CLI commands. This is due to insufficient input validation, which could enable an attacker to read, write, and overwrite any file on the system or execute arbitrary code. To exploit this, an attacker must authenticate and have local access to the targeted device.
Recommendations For version 7.0(240.0), update to a newer version that includes the fix for this issue, as confirmed by Cisco. As a temporary workaround, consider restricting access to the CLI to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00559
CVE-2015-4224

Produtos afetados

Cisco Wireless Lan Controller
Cisco Wls