PT-2017-17187 · Cisco · Cisco Integrated Management Controller
Publicado
2017-04-20
·
Atualizado
2019-10-09
·
CVE-2017-6616
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Integrated Management Controller (IMC) version 3.0(1c)
Description
A vulnerability in the web-based GUI could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The issue exists because the software does not sufficiently sanitize specific values received as part of a user-supplied HTTP request. An attacker could exploit this by sending a crafted HTTP request. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system.
Recommendations
For Cisco Integrated Management Controller (IMC) version 3.0(1c), update the software to a version that includes the fix for Cisco Bug ID: CSCvd14578.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Integrated Management Controller