Lucene search

K
seebugRootSSV:61609
HistoryFeb 28, 2014 - 12:00 a.m.

Cisco Prime Infrastructure任意命令执行漏洞(CVE-2014-0679)

2014-02-2800:00:00
Root
www.seebug.org
23

EPSS

0.002

Percentile

51.9%

BUGTRAQ ID: 65816
CVE(CAN) ID: CVE-2014-0679

Cisco Prime Infrastructure是通过思科技术LMS和NCS进行无线管理的解决方案。

Cisco Prime Infrastructure没有正确验证URL请求,未经身份验证的远程攻击者可以root级别的权限执行任意命令。
0
Cisco Prime Infrastructure 2.0
Cisco Prime Infrastructure 1.4
Cisco Prime Infrastructure 1.3
Cisco Prime Infrastructure 1.2
厂商补丁:

Cisco

Cisco已经为此发布了一个安全公告(cisco-sa-20140226-pi)以及相应补丁:
cisco-sa-20140226-pi:Cisco Prime Infrastructure Command Execution Vulnerability
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140226-pi

EPSS

0.002

Percentile

51.9%