PT-2017-17187 · Cisco · Cisco Integrated Management Controller

Published

2017-04-20

·

Updated

2019-10-09

·

CVE-2017-6616

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) version 3.0(1c)
Description A vulnerability in the web-based GUI could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The issue exists because the software does not sufficiently sanitize specific values received as part of a user-supplied HTTP request. An attacker could exploit this by sending a crafted HTTP request. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system.
Recommendations For Cisco Integrated Management Controller (IMC) version 3.0(1c), update the software to a version that includes the fix for Cisco Bug ID: CSCvd14578.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6616

Affected Products

Cisco Integrated Management Controller