Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.140311
Categoría:CISCO
Título:Cisco Unified Communications Manager Horizontal Privilege Escalation Vulnerability (cisco-sa-20170816-ucm)
Resumen:A vulnerability in configuration modification permissions; validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker; to perform a horizontal privilege escalation where one user can modify another user's; configuration.
Descripción:Summary:
A vulnerability in configuration modification permissions
validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker
to perform a horizontal privilege escalation where one user can modify another user's
configuration.

Vulnerability Insight:
The vulnerability is due to lack of proper Role Based Access
Control (RBAC) when certain user configuration changes are requested. An attacker could exploit
this vulnerability by sending an authenticated, crafted HTTP request to the targeted
application.

Vulnerability Impact:
An exploit could allow the attacker to impact the integrity of
the application where one user can modify the configuration of another user's information.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-6785
BugTraq ID: 100375
http://www.securityfocus.com/bid/100375
Cisco Security Advisory: 20170816 Cisco Unified Communications Manager Horizontal Privilege Escalation Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-ucm
http://www.securitytracker.com/id/1039184
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.