Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
BID:62485
Info
Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
| Bugtraq ID: | 62485 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5490 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2013 12:00AM |
| Updated: | Sep 18 2013 12:00AM |
| Credit: | Ben Williams of NCC Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
Cisco Prime Data Center Network Manager is prone to an XML External Entity injection vulnerability.
An attacker can exploit this issue to gain access to arbitrary text files on the underlying operating system with root privileges. Information obtained may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCud80148.
Cisco Prime Data Center Network Manager is prone to an XML External Entity injection vulnerability.
An attacker can exploit this issue to gain access to arbitrary text files on the underlying operating system with root privileges. Information obtained may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCud80148.
Exploit / POC
Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Prime Data Center Network Manager XML External Entity Injection Vulnerability
References:
References: