SB2018011908 - Multiple vulnerabilities in Cisco Prime Infrastructure
Published: January 19, 2018
Security Bulletin ID
SB2018011908
Severity
Low
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Privilege escalation (CVE-ID: CVE-2018-0096)
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.The weakness exists in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure due to failure to properly enforce RBAC for virtual domains. A remote attacker can send an authenticated, crafted HTTP request to a targeted application,bypass RBAC policies, modify a virtual domain and access resources that are not normally accessible.
2) Open redirect (CVE-ID: CVE-2018-0097)
The vulnerability allows a remote attacker to redirect the target user to external websites.The vulnerability exists in the web interface of Cisco Prime Infrastructure due to improper input validation of the parameters in the HTTP request. A remote attacker can use a specially crafted HTTP request that could cause the web application to redirect the request to a specific malicious URL.
Remediation
Install update from vendor's website.