Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106656
Categoría:CISCO
Título:Cisco Prime Infrastructure API Credentials Management Vulnerability
Resumen:A vulnerability in the APIs for Cisco Prime Infrastructure could allow an;authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker;needs to have valid credentials.
Descripción:Summary:
A vulnerability in the APIs for Cisco Prime Infrastructure could allow an
authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker
needs to have valid credentials.

Vulnerability Insight:
The vulnerability is due to a lack of proper role-based access control
(RBAC) for certain APIs in the application. An attacker could exploit this vulnerability by authenticating to
specific APIs as a low-privileged user.

Vulnerability Impact:
An exploit could allow the attacker to view or modify system configuration
information. The API usage should be restricted based on the user's privilege level.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-3869
BugTraq ID: 96931
http://www.securityfocus.com/bid/96931
http://www.securitytracker.com/id/1038048
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.