Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105708
Categoría:CISCO
Título:Cisco NX-OS Software DHCP Options Command Injection Vulnerability (Cisco-SA-20150327-CVE-2015-0658)
Resumen:A vulnerability in DHCP code used with PowerOn Auto; Provisioning (POAP) of Cisco NX-OS could allow an unauthenticated, adjacent attacker to inject; arbitrary commands into the Cisco NX-OS device.
Descripción:Summary:
A vulnerability in DHCP code used with PowerOn Auto
Provisioning (POAP) of Cisco NX-OS could allow an unauthenticated, adjacent attacker to inject
arbitrary commands into the Cisco NX-OS device.

Vulnerability Insight:
The vulnerability is due to insufficient input validation of
the DHCP options returned as a result of POAP. An attacker could exploit this vulnerability by
responding to the initial DHCP request initiated as part of POAP with crafted DHCP packets.

Vulnerability Impact:
An exploit could allow the attacker to execute arbitrary
commands in the security context of the root user. The attack can occur during the POAP
initialization process.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.9

CVSS Vector:
AV:A/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-0658
Cisco Security Advisory: 20150327 Cisco NX-OS Software DHCP Options Command Injection Vulnerability
http://tools.cisco.com/security/center/viewAlert.x?alertId=38062
http://www.securitytracker.com/id/1031992
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.