Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106851
Category:CISCO
Title:Cisco Prime Data Center Network Manager Debug Remote Code Execution Vulnerability
Summary:A vulnerability in the role-based access control (RBAC) functionality of;Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access;sensitive information or execute arbitrary code with root privileges on an affected system.
Description:Summary:
A vulnerability in the role-based access control (RBAC) functionality of
Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access
sensitive information or execute arbitrary code with root privileges on an affected system.

Vulnerability Insight:
The vulnerability is due to the lack of authentication and authorization
mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could
exploit this vulnerability by remotely connecting to the debugging tool via TCP.

Vulnerability Impact:
A successful exploit could allow the attacker to access sensitive information
about the affected software or execute arbitrary code with root privileges on the affected system.

Solution:
Update to Cisco Prime DCNM Software releases 10.2(1) or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6639
BugTraq ID: 98935
http://www.securityfocus.com/bid/98935
http://www.securitytracker.com/id/1038626
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.