The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.
References
Configurations
History
21 Nov 2024, 02:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-csp2100-1 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/93093 - | |
References | () http://www.securitytracker.com/id/1036865 - |
Information
Published : 2016-09-22 22:59
Updated : 2024-11-21 02:56
NVD link : CVE-2016-6373
Mitre link : CVE-2016-6373
CVE.ORG link : CVE-2016-6373
JSON object : View
Products Affected
cisco
- cloud_services_platform_2100
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')