QID 731276
QID 731276: Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation Vulnerability (cisco-sa-thouseyes-privesc-DmzHG3Qv)
A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
Affected Versions:
ThousandEyes Enterprise Agent versions prior to 0.233.2
QID Detection Logic:
Unauthenticated: This QID checks for the version of ThousandEyes Enterprise Agent on the target.
A successful exploit could allow the attacker to execute arbitrary commands and elevate privileges to root.
Solution
Customers are advised to refer to cisco-sa-thouseyes-privesc-DmzHG3Qv for further updates.
Vendor References
- cisco-sa-thouseyes-privesc-DmzHG3Qv -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thouseyes-privesc-DmzHG3Qv
CVEs related to QID 731276
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-thouseyes-privesc-DmzHG3Qv |
|