Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106721
Categoría:CISCO
Título:Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers Shell Bypass Vulnerability
Resumen:A vulnerability in the CLI command parser of the Cisco Mobility Express 2800;and 3800 Series Wireless LAN Controllers could allow an authenticated, local attacker to obtain access to the;underlying operating system shell with root-level privileges.
Descripción:Summary:
A vulnerability in the CLI command parser of the Cisco Mobility Express 2800
and 3800 Series Wireless LAN Controllers could allow an authenticated, local attacker to obtain access to the
underlying operating system shell with root-level privileges.

Vulnerability Insight:
The vulnerability is due to incorrect permissions being assigned to
configured users on the device. An attacker could exploit this vulnerability by authenticating to the device and
issuing certain commands at the CLI.

Vulnerability Impact:
A successful exploit could allow the attacker to access the underlying
operating system shell with root access.

Solution:
See vendor advisory.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-9197
BugTraq ID: 97469
http://www.securityfocus.com/bid/97469
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.