Overview
The Cisco Prime Infrastructure version 2.2 contains two binaries with SUID root world-executable privileges, allowing any local user to execute arbitrary commands as root.
Description
CWE-276: Incorrect Default Permissions Two binaries are included in Cisco Prime version 2.2 that run as SUID root with world-executable privileges. The commands are |
Impact
A remote authenticated user may escalate privileges to root and execute arbitrary commands. |
Solution
Apply an update |
Restrict executable permissions |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 8.5 | E:H/RL:W/RC:C |
Environmental | 6.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Jeremy Brown for reporting this issue.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | None |
Date Public: | 2015-07-31 |
Date First Published: | 2015-08-17 |
Date Last Updated: | 2015-08-17 19:26 UTC |
Document Revision: | 57 |