Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106327
Categoría:CISCO
Título:Cisco Prime Infrastructure Authentication Bypass API Vulnerability
Resumen:A vulnerability in the application programming interface (API) of Cisco;Prime Infrastructure could allow an unauthenticated, remote attacker to access and control the API resources.
Descripción:Summary:
A vulnerability in the application programming interface (API) of Cisco
Prime Infrastructure could allow an unauthenticated, remote attacker to access and control the API resources.

Vulnerability Insight:
The vulnerability is due to improper input validation of HTTP requests for
unauthenticated URIs. An attacker could exploit this vulnerability by sending a crafted HTTP request to the
affected URIs.

Vulnerability Impact:
Successful exploitation of this vulnerability could allow the attacker to
upload malicious code to the application server or read unauthorized management data, such as credentials of
devices managed by Cisco Prime Infrastructure.

Affected Software/OS:
Cisco Prime Infrastructure software versions 1.2 through version 3.0.

Solution:
Upgrade to version 2.2.3 Update 4, 3.0.3 Update 2, or later

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-1289
BugTraq ID: 91504
http://www.securityfocus.com/bid/91504
Cisco Security Advisory: 20160629 Cisco Prime Infrastructure and Evolved Programmable Network Manager Authentication Bypass API Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-piauthbypass
http://www.securitytracker.com/id/1036195
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.