Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
BID:68307
Info
Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 68307 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3307 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2014 12:00AM |
| Updated: | Jul 01 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
Cisco Small Cell Engine is prone to a remote arbitrary command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands and completely compromise the affected device.
This issue is being tracked by Cisco Bug ID CSCup47513.
Cisco Small Cell Engine is prone to a remote arbitrary command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands and completely compromise the affected device.
This issue is being tracked by Cisco Bug ID CSCup47513.
Exploit / POC
Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Small Cell DHCP Message Processing Remote Arbitrary Command Execution Vulnerability
References:
References: