SB2016072101 - Input validation vulnerability in Cisco Unified Computing System Performance Manager in Cisco Unified Computing System Performance Manager
Published: July 21, 2016
Security Bulletin ID
SB2016072101
Severity
Critical
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation vulnerability in Cisco Unified Computing System Performance Manager (CVE-ID: CVE-2016-1374)
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.The vulnerability exists due to insufficient input validation performed on parameters that are passed via an HTTP GET request. A remote authenticated attacker can execute arbitrary commands with the privileges of the root user by sending crafted HTTP GET requests to an affected system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.