Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
BID:19075
CVE-2006-3733 |Info
Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
| Bugtraq ID: | 19075 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2006 12:00AM |
| Updated: | Jul 20 2006 09:57PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
Nortel Networks Contivity 2000 VPN Switch 4.1.3 Nortel Networks Contivity 2000 VPN Switch 4.1.2 Nortel Networks Contivity 2000 VPN Switch 4.1 Cisco CS-MARS 4.1.5 |
| Not Vulnerable: |
Cisco CS-MARS 4.2.1 |
Discussion
Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
Cisco Security Monitoring, Analysis and Response System (CS-MARS) is prone to a vulnerability that could permit the execution of arbitrary commands.
An attacker could exploit this issue to execute arbitrary commands with administrative privileges. This may facilitate a remote compromise of the affected appliance.
Cisco has released version 4.2.1 to address this issue; prior versions are reported vulnerable.
This issue was previously discussed in BID 19071 (Cisco Security Monitoring Analysis and Response System Multiple Vulnerabilities), which has subsequently been split into individual records.
Cisco Security Monitoring, Analysis and Response System (CS-MARS) is prone to a vulnerability that could permit the execution of arbitrary commands.
An attacker could exploit this issue to execute arbitrary commands with administrative privileges. This may facilitate a remote compromise of the affected appliance.
Cisco has released version 4.2.1 to address this issue; prior versions are reported vulnerable.
This issue was previously discussed in BID 19071 (Cisco Security Monitoring Analysis and Response System Multiple Vulnerabilities), which has subsequently been split into individual records.
Exploit / POC
Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
An attacker can exploit this issue using a web client.
The following exploit script code is available:
An attacker can exploit this issue using a web client.
The following exploit script code is available:
Solution / Fix
Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
Solution:
Fixes are available. Please see the referenced Cisco advisory for details.
Solution:
Fixes are available. Please see the referenced Cisco advisory for details.
References
Cisco Security Monitoring Analysis and Response System JBoss Command Execution Vulnerability
References:
References:
- Cisco Call Manager Express (Cisco Systems)
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Monitoring, (Cisco)
- Cisco Security Monitoring, Analysis and Response System Homepage (Cisco)
- Securing JBoss (JBoss)
- Cisco MARS < 4.2.1 remote compromise (Jon Hart
) - Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Monitoring, (Cisco)