PT-2017-12427 · Cisco · Cisco Cloud Services Platform (Csp) 2100
Publicado
2017-10-19
·
Atualizado
2019-10-09
·
CVE-2017-12251
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Cloud Services Platform (CSP) 2100 versions 2.1.0 through 2.2.2
Description
A weakness in the generation of certain authentication mechanisms in the URL of the web console could allow an authenticated, remote attacker to interact maliciously with services or virtual machines operating on an affected device. The attacker could exploit this by browsing to a hosted VM's URL and viewing specific patterns that control the web application's authentication mechanisms. This could allow the attacker to access a specific VM, resulting in a complete loss of the system's confidentiality, integrity, and availability.
Recommendations
For Cisco Cloud Services Platform (CSP) 2100 versions 2.1.0 through 2.2.2, consider restricting access to the web console until a fix is available. As a temporary workaround, limit interactions with the services or virtual machines operating on the affected CSP device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Cloud Services Platform (Csp) 2100