CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
95.8%
Cisco Prime LAN Management Solution (LMS) Virtual Appliance
contains a vulnerability that could allow an unauthenticated, remote
attacker to execute arbitrary commands with the privileges of the root user. The
vulnerability is due to improper validation of authentication and
authorization commands sent to certain TCP ports. An attacker
could exploit this vulnerability by connecting to the affected system
and sending arbitrary commands.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate these vulnerabilities are available.
This advisory is available at the following link:
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | prime_lan_management_solution | any | cpe:2.3:a:cisco:prime_lan_management_solution:any:*:*:*:*:*:*:* |