Lucene search

K
ciscoCiscoCISCO-SA-20160601-PRIME2
HistoryJun 01, 2016 - 4:00 p.m.

Cisco Prime Network Analysis Module Authenticated Remote Code Execution Vulnerability

2016-06-0116:00:00
tools.cisco.com
18

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.6%

A vulnerability in the web interface of Cisco Prime Network Analysis Module (NAM) and Cisco Prime Virtual Network Analysis Module (vNAM) could allow an authenticated, remote attacker to execute arbitrary commands or code on the host operating system with the privileges of the web server.

The vulnerability is due to insufficient sanitization of user-supplied input before the input is used in subsequent operations. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary commands or code on the host operating system with the reduced privileges of the web server.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime2[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime2”]

Affected configurations

Vulners
Node
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscoprime_virtual_network_analysis_module_softwareMatchany
OR
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscoprime_virtual_network_analysis_module_softwareMatchany
VendorProductVersionCPE
ciscoprime_network_analysis_module_softwareanycpe:2.3:a:cisco:prime_network_analysis_module_software:any:*:*:*:*:*:*:*
ciscoprime_virtual_network_analysis_module_softwareanycpe:2.3:a:cisco:prime_virtual_network_analysis_module_software:any:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.6%

Related for CISCO-SA-20160601-PRIME2