SB2018011908 - Multiple vulnerabilities in Cisco Prime Infrastructure



SB2018011908 - Multiple vulnerabilities in Cisco Prime Infrastructure

Published: January 19, 2018

Security Bulletin ID SB2018011908
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Privilege escalation (CVE-ID: CVE-2018-0096)

The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.

The weakness exists in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure  due to failure to properly enforce RBAC for virtual domains. A remote attacker can send an authenticated, crafted HTTP request to a targeted application,bypass RBAC policies, modify a virtual domain and access resources that are not normally accessible.

2) Open redirect (CVE-ID: CVE-2018-0097)

The vulnerability allows a remote attacker to redirect the target user to external websites.

The vulnerability exists in the web interface of Cisco Prime Infrastructure due to improper input validation of the parameters in the HTTP request. A remote attacker can use a specially crafted HTTP request that could cause the web application to redirect the request to a specific malicious URL.

Remediation

Install update from vendor's website.