Wednesday, July 5, 2017

Cisco FireSIGHT System Software Arbitrary Code Execution Vulnerability

A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system.

The vulnerability is due to improper handling of modified backup configuration files. An attacker could exploit this vulnerability by modifying certain components within the backup system files. An exploit could allow the attacker to run arbitrary code as a root user on the affected appliance.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2uqbpO0 A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system.

The vulnerability is due to improper handling of modified backup configuration files. An attacker could exploit this vulnerability by modifying certain components within the backup system files. An exploit could allow the attacker to run arbitrary code as a root user on the affected appliance.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2uqbpO0
Security Impact Rating: Medium
CVE: CVE-2017-6735

from Cisco Security Advisory http://ift.tt/2uqbpO0

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.