Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
BID:101993
Info
Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
| Bugtraq ID: | 101993 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12352 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:37PM |
| Credit: | Tomas Lazauninkas of the Swedbank Security Verification Team. |
| Vulnerable: |
Cisco Application Policy Infrastructure Controller (APIC) 2.3(1f) |
| Not Vulnerable: | |
Discussion
Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
.Cisco Application Policy Infrastructure Controller is prone a local command-injection and privilege escalation vulnerability.
An attacker can exploit this issue to execute commands and gain elevated privileges.
The issue is being tracked by Cisco Bug ID CSCvf57274.
.Cisco Application Policy Infrastructure Controller is prone a local command-injection and privilege escalation vulnerability.
An attacker can exploit this issue to execute commands and gain elevated privileges.
The issue is being tracked by Cisco Bug ID CSCvf57274.
Exploit / POC
Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Application Policy Infrastructure Controller Local Command Injection and Privilege Escalation
References:
References: