PT-2017-3756 · Cisco · Cisco Secure Access Control System
Mikhail Klyuchnikov
+2
·
Publicado
2017-06-01
·
Atualizado
2019-10-09
·
CVE-2018-0253
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco Secure Access Control System (ACS) versions prior to 5.8 Patch 7
Description:
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. The issue is due to insufficient validation of the Action Message Format (AMF) protocol. An attacker could exploit this by sending a crafted AMF message that contains malicious code to a targeted user, allowing the execution of arbitrary commands on the ACS device.
Recommendations:
For versions prior to 5.8 Patch 7, update to Release 5.8 Patch 7 or later to resolve the issue. As a temporary workaround, consider restricting access to the AMF protocol to minimize the risk of exploitation. Avoid using the AMF protocol until the issue is resolved.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Secure Access Control System