PT-2017-16106 · Cisco · Cisco Ucs Director

Publicado

2017-02-15

·

Atualizado

2019-10-03

·

CVE-2017-3801

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco UCS Director versions 6.0.0.0 through 6.0.0.1
Description A privilege escalation issue exists due to improper role-based access control (RBAC) after the Developer Menu is enabled. An authenticated, local attacker with an end-user profile could enable Developer Mode, add new catalogs with arbitrary workflow items, and perform actions defined by these items, including those affecting other tenants.
Recommendations For Cisco UCS Director versions 6.0.0.0 and 6.0.0.1, consider disabling the Developer Menu to prevent exploitation until a patch is available. Restrict access to the Developer Mode feature to minimize the risk of privilege escalation. Avoid enabling Developer Mode for end-user profiles to prevent attackers from adding arbitrary workflow items.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3801

Produtos afetados

Cisco Ucs Director