SB2016072101 - Input validation vulnerability in Cisco Unified Computing System Performance Manager in Cisco Unified Computing System Performance Manager



SB2016072101 - Input validation vulnerability in Cisco Unified Computing System Performance Manager in Cisco Unified Computing System Performance Manager

Published: July 21, 2016

Security Bulletin ID SB2016072101
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation vulnerability in Cisco Unified Computing System Performance Manager (CVE-ID: CVE-2016-1374)

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to insufficient input validation performed on parameters that are passed via an HTTP GET request. A remote authenticated attacker can execute arbitrary commands with the privileges of the root user by sending crafted HTTP GET requests to an affected system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install update from vendor's website.