Wednesday, July 5, 2017

Cisco Prime Network Information Disclosure Vulnerability

A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, which could lead to the disclosure of confidential information.

The vulnerability is due to a lack of input and validation checking mechanisms in the system. An attacker could exploit this vulnerability by issuing specific, known commands after authenticating locally to the system via the CLI. A successful exploit could allow the attacker to view confidential information that should only be visible to authenticated users.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2upWcfK A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, which could lead to the disclosure of confidential information.

The vulnerability is due to a lack of input and validation checking mechanisms in the system. An attacker could exploit this vulnerability by issuing specific, known commands after authenticating locally to the system via the CLI. A successful exploit could allow the attacker to view confidential information that should only be visible to authenticated users.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2upWcfK
Security Impact Rating: Medium
CVE: CVE-2017-6726

from Cisco Security Advisory http://ift.tt/2upWcfK

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.