Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.106604
Kategorie:CISCO
Titel:Cisco UCS Director Privilege Escalation Vulnerability
Zusammenfassung:A vulnerability in the web-based GUI of Cisco UCS Director could allow an; authenticated, local attacker to execute arbitrary workflow items with just an end-user profile.
Beschreibung:Summary:
A vulnerability in the web-based GUI of Cisco UCS Director could allow an
authenticated, local attacker to execute arbitrary workflow items with just an end-user profile.

Vulnerability Insight:
The vulnerability is due to improper role-based access control (RBAC) after
the Developer Menu is enabled in Cisco UCS Director. An attacker could exploit this vulnerability by enabling
Developer Mode for his/her user profile with an end-user profile and then adding new catalogs with arbitrary
workflow items to his/her profile.

Vulnerability Impact:
An exploit could allow an attacker to perform any actions defined by these
workflow items, including actions affecting other tenants.

Solution:
Update to version 6.0.1.0 or later.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-3801
BugTraq ID: 96235
http://www.securityfocus.com/bid/96235
http://www.securitytracker.com/id/1037830
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.