PT-2017-17187 · Cisco · Cisco Integrated Management Controller

Publicado

2017-04-20

·

Atualizado

2019-10-09

·

CVE-2017-6616

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) version 3.0(1c)
Description A vulnerability in the web-based GUI could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The issue exists because the software does not sufficiently sanitize specific values received as part of a user-supplied HTTP request. An attacker could exploit this by sending a crafted HTTP request. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system.
Recommendations For Cisco Integrated Management Controller (IMC) version 3.0(1c), update the software to a version that includes the fix for Cisco Bug ID: CSCvd14578.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6616

Produtos afetados

Cisco Integrated Management Controller