PT-2017-17187 · Cisco · Cisco Integrated Management Controller
Published
2017-04-20
·
Updated
2019-10-09
·
CVE-2017-6616
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Integrated Management Controller (IMC) version 3.0(1c)
Description
A vulnerability in the web-based GUI could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The issue exists because the software does not sufficiently sanitize specific values received as part of a user-supplied HTTP request. An attacker could exploit this by sending a crafted HTTP request. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system.
Recommendations
For Cisco Integrated Management Controller (IMC) version 3.0(1c), update the software to a version that includes the fix for Cisco Bug ID: CSCvd14578.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Integrated Management Controller