Lucene search

K
ciscoCiscoCISCO-SA-20151109-CG-NMS
HistoryNov 09, 2015 - 12:00 a.m.

Cisco Connected Grid Network Management System Privilege Escalation Vulnerability

2015-11-0900:00:00
tools.cisco.com
15

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

31.9%

A vulnerability in the web GUI of Cisco Connected Grid Network Management System could allow an authenticated, remote attacker to perform limited configuration changes while logged in as a user having the Monitor-Only role.

The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the related configuration pages on the web interface and submitting the changes. An exploit could allow the attacker to make unauthorized modifications to the targeted system.

Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151109-cg-nms[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151109-cg-nms”]

Affected configurations

Vulners
Node
ciscoconnected_grid_network_management_systemMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
VendorProductVersionCPE
ciscoconnected_grid_network_management_systemanycpe:2.3:a:cisco:connected_grid_network_management_system:any:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

31.9%

Related for CISCO-SA-20151109-CG-NMS