Lucene search

K
ciscoCiscoCISCO-SA-20130710-CVE-2013-3408
HistoryJul 10, 2013 - 1:57 p.m.

Cisco Virtualization Experience Client Privilege Escalation Vulnerability

2013-07-1013:57:18
tools.cisco.com
11

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.001

Percentile

25.6%

A vulnerability in the function handling the operating system permissions of Cisco Virtualization Experience Client 6000 Series could allow an authenticated, local attacker to take full control of the affected system.

The vulnerability is due to improper implementation of the permissions for the underlying operating system. An attacker could exploit this vulnerability by logging in to the system and executing a series of commands that could lead to escalated privileges. An exploit could allow the unprivileged attacker to escalate privileges and take full control of the affected system.

Cisco has confirmed the vulnerability in a security notice and has released software updates.

To exploit this vulnerability, an attacker requires authenticated access to the targeted system and the ability to authenticate to a privileged security context. Authenticated access may require the attacker to access trusted, internal networks. These access requirements could limit the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscovirtualization_experience_client_6000_series_firmwareMatchany
OR
ciscovirtualization_experience_client_6000Match6000_series_firmware
VendorProductVersionCPE
ciscovirtualization_experience_client_6000_series_firmwareanycpe:2.3:o:cisco:virtualization_experience_client_6000_series_firmware:any:*:*:*:*:*:*:*
ciscovirtualization_experience_client_60006000_series_firmwarecpe:2.3:h:cisco:virtualization_experience_client_6000:6000_series_firmware:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.001

Percentile

25.6%

Related for CISCO-SA-20130710-CVE-2013-3408