PT-2023-2199 · Cisco · Cisco Evolved Programmable Network Manager+2

Sean Morland

·

Publicado

2023-04-05

·

Atualizado

2023-04-12

·

CVE-2023-20121

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Evolved Programmable Network Manager (affected versions not specified) Cisco Identity Services Engine (affected versions not specified) Cisco Prime Infrastructure (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the restricted shell of the affected Cisco products. These vulnerabilities could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. The vulnerabilities exist due to the lack of measures to neutralize special elements used in the operating system command.
Recommendations For Cisco Evolved Programmable Network Manager, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Cisco Identity Services Engine, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Cisco Prime Infrastructure, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01944
CVE-2023-20121

Produtos afetados

Cisco Evolved Programmable Network Manager
Cisco Identity Services Engine
Cisco Prime Infrastructure