PT-2022-1436 · Cisco · Cisco Tetration
Published
2022-01-12
·
Updated
2024-11-18
·
CVE-2022-20652
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Tetration (affected versions not specified)
Description
The issue is related to insufficient input validation in the web-based management interface and API subsystem, allowing an authenticated, remote attacker to inject arbitrary commands with root-level privileges on the underlying operating system. This can be achieved by submitting a crafted HTTP message to the affected system. The attacker needs valid administrator-level credentials to exploit this issue.
Recommendations
To resolve the issue, apply the software updates released by Cisco that address this vulnerability.
At the moment, there is no information about additional mitigation measures or workarounds that address this vulnerability.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Tetration