The vulnerability exists because the password change request is not fully qualified. An authenticated attacker with a user role other than Administrator could exploit this vulnerability by sending a specially crafted HTTP request to the Cisco PRSM. An exploit could allow the attacker to change the password of any user on the system, including users with the Administrator role.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link: http://ift.tt/1NQ2FS2
from Cisco Security Advisory http://ift.tt/1NQ2FS2
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.