QID 730777
Date Published: 2023-04-24
QID 730777: Cisco Prime Infrastructure Command Injection Vulnerability (cisco-sa-adeos-MLAyEcvk)
A vulnerability in the restricted shell of Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
Affected Products
Cisco Prime Infrastructure releases earlier than Release Earlier than 3.10.4
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"
A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of the affected device.
Solution
Customers are advised to refer to cisco-sa-adeos-MLAyEcvk for more information.
Vendor References
- cisco-sa-adeos-MLAyEcvk -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk
CVEs related to QID 730777
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-adeos-MLAyEcvk |
|