Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
BID:101996
Info
Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 101996 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12343 CVE-2017-12344 CVE-2017-12345 CVE-2017-12346 CVE-2017-12347 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:37PM |
| Credit: | Indrajith.A.N |
| Vulnerable: |
Cisco MDS 9500 Series Multilayer Directors 10.3(1)S3 Cisco MDS 9500 Series Multilayer Directors 10.2(1) Cisco Data Center Network Manager 0 |
| Not Vulnerable: |
Cisco MDS 9500 Series Multilayer Directors 11.0(0.238)S0 Cisco MDS 9500 Series Multilayer Directors 10.4(1.65)S0 Cisco MDS 9500 Series Multilayer Directors 10.4(1.41)S0 Cisco MDS 9500 Series Multilayer Directors 10.4(1.40)S0 Cisco MDS 9500 Series Multilayer Directors 10.4(1.34)S0 Cisco MDS 9500 Series Multilayer Directors 10.4(1)S9 Cisco MDS 9500 Series Multilayer Directors 10.4(1)S19 Cisco MDS 9500 Series Multilayer Directors 10.4(1)S11 Cisco MDS 9500 Series Multilayer Directors 10.3(1)R(0.79) Cisco MDS 9500 Series Multilayer Directors 10.3(1)R(0.74) |
Discussion
Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
Cisco Data Center Network Manager is prone to multiple remote security vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected system, manipulate and spoof content, insert a crafted HTTP header into an HTTP response to cause a web page redirection to a possible malicious website, and/or to execute arbitrary HTML or script code in the browser of an unsuspecting user in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; this may aid in launching further attacks.
These issues are being tracked by Cisco Bug ID's CSCvf40477, CSCvf63150, CSCvf68218, CSCvf68235 and CSCvf68247.
Cisco Data Center Network Manager is prone to multiple remote security vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected system, manipulate and spoof content, insert a crafted HTTP header into an HTTP response to cause a web page redirection to a possible malicious website, and/or to execute arbitrary HTML or script code in the browser of an unsuspecting user in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; this may aid in launching further attacks.
These issues are being tracked by Cisco Bug ID's CSCvf40477, CSCvf63150, CSCvf68218, CSCvf68235 and CSCvf68247.
Exploit / POC
Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Data Center Network Manager Multiple Remote Security Vulnerabilities
References:
References: