Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
BID:48810
Info
Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
| Bugtraq ID: | 48810 |
| Class: | Design Error |
| CVE: |
CVE-2011-2547 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2011 12:00AM |
| Updated: | Jul 27 2011 06:00PM |
| Credit: | Michal Sajdak |
| Vulnerable: |
Cisco SA540 2.1.18 Cisco SA520W 2.1.18 Cisco SA520 2.1.18 |
| Not Vulnerable: |
Cisco SA540 2.1.19 Cisco SA520W 2.1.19 Cisco SA520 2.1.19 |
Discussion
Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
Cisco SA 500 series security appliances are prone to a remote command-injection vulnerability that affects their Web-based management interface.
An authenticated attacker can exploit this issue to execute arbitrary commands with root-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug ID CSCtq65681.
The following devices are affected:
Cisco SA520
Cisco SA520W
Cisco SA540
Cisco SA 500 series security appliances are prone to a remote command-injection vulnerability that affects their Web-based management interface.
An authenticated attacker can exploit this issue to execute arbitrary commands with root-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug ID CSCtq65681.
The following devices are affected:
Cisco SA520
Cisco SA520W
Cisco SA540
Exploit / POC
Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco SA 500 Series Appliances Web Management Interface Remote Command Injection Vulnerability
References:
References: