Lucene search

K
ciscoCiscoCISCO-SA-STEALTH-RCE-2HYB9KFK
HistoryMay 18, 2022 - 4:00 p.m.

Cisco Secure Network Analytics Remote Code Execution Vulnerability

2022-05-1816:00:00
tools.cisco.com
20
cisco
secure network analytics
remote code execution
vulnerability
web-based management interface
arbitrary commands
administrator
operating system
user input validation
software updates
configuration changes
authentication
cisco secure
security products
advisory link

EPSS

0.001

Percentile

49.0%

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system.

This vulnerability is due to insufficient user input validation by the web-based management interface of the affected software. An attacker could exploit this vulnerability by injecting arbitrary commands in the web-based management interface. A successful exploit could allow the attacker to make configuration changes on the affected device or cause certain services to restart unexpectedly.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK”]

Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see Meet Cisco Secure [“https://www.cisco.com/c/en/us/products/security/secure-names.html”].

Affected configurations

Vulners
Node
ciscostealthwatch_enterpriseMatchany
OR
ciscosecure_network_analyticsMatchany
OR
ciscostealthwatch_enterpriseMatchany
OR
ciscosecure_network_analyticsMatchany
VendorProductVersionCPE
ciscostealthwatch_enterpriseanycpe:2.3:a:cisco:stealthwatch_enterprise:any:*:*:*:*:*:*:*
ciscosecure_network_analyticsanycpe:2.3:a:cisco:secure_network_analytics:any:*:*:*:*:*:*:*

EPSS

0.001

Percentile

49.0%

Related for CISCO-SA-STEALTH-RCE-2HYB9KFK