Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
BID:100932
CVE-2017-12255 |Info
Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
| Bugtraq ID: | 100932 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12255 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 20 2017 12:00AM |
| Updated: | Sep 20 2017 12:00AM |
| Credit: | Cisco. |
| Vulnerable: |
Cisco UCS Central Software 1.5(1c) |
| Not Vulnerable: |
Cisco UCS Central Software 2.0(1b) |
Discussion
Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
Cisco UCS Central Software is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and gain shell access.
This issue is being tracked by Cisco bug ID CSCve70762.
Cisco UCS Central Software is prone to a local command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to bypass the CLI restrictions and gain shell access.
This issue is being tracked by Cisco bug ID CSCve70762.
Exploit / POC
Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
References:
References: