Lucene search

K
ciscoCiscoCISCO-SA-20160601-PRIME
HistoryJun 01, 2016 - 4:00 p.m.

Cisco Prime Network Analysis Module Unauthenticated Remote Code Execution Vulnerability

2016-06-0116:00:00
tools.cisco.com
22

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.6%

A vulnerability in the web interface of Cisco Network Analysis Modules could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of the affected device with the privileges of the web server.

The vulnerability is due to a failure to properly sanitize user input prior to executing an external command derived from the input. An attacker could exploit the vulnerability by submitting a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands or code on the underlying operating system with the reduced privileges of the web server.

Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime”]

Affected configurations

Vulners
Node
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscoprime_virtual_network_analysis_module_softwareMatchany
OR
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscoprime_virtual_network_analysis_module_softwareMatchany
VendorProductVersionCPE
ciscoprime_network_analysis_module_softwareanycpe:2.3:a:cisco:prime_network_analysis_module_software:any:*:*:*:*:*:*:*
ciscoprime_virtual_network_analysis_module_softwareanycpe:2.3:a:cisco:prime_virtual_network_analysis_module_software:any:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.6%

Related for CISCO-SA-20160601-PRIME