Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
BID:38500
Info
Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 38500 |
| Class: | Design Error |
| CVE: |
CVE-2010-0571 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2010 12:00AM |
| Updated: | Mar 03 2010 12:00AM |
| Credit: | National Australia Bank's Security Assurance team. |
| Vulnerable: |
Cisco Digital Media Manager (DMM) 5.1 Cisco Digital Media Manager (DMM) 5.0 |
| Not Vulnerable: |
Cisco Digital Media Manager (DMM) 5.2 |
Discussion
Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
Cisco Digital Media Manager (DMM) is prone to a remote privilege escalation vulnerability. This issue is tracked by Cisco Bug ID CSCtc46008.
An authenticated attacker can exploit this issue to modify application configuration settings, gaining elevated privileges. This may lead to a full compromise of the affected computer or aid in further attacks.
Cisco Digital Media Manager 5.0 and 5.1 are vulnerable.
Cisco Digital Media Manager (DMM) is prone to a remote privilege escalation vulnerability. This issue is tracked by Cisco Bug ID CSCtc46008.
An authenticated attacker can exploit this issue to modify application configuration settings, gaining elevated privileges. This may lead to a full compromise of the affected computer or aid in further attacks.
Cisco Digital Media Manager 5.0 and 5.1 are vulnerable.
Exploit / POC
Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
Attackers can exploit this issue using readily available networking tools.
Attackers can exploit this issue using readily available networking tools.
Solution / Fix
Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
References:
References: