ID:1837 - Exploit for Arbitrary Command Execution - CVE-2016-6433

 
Main Vulnerability Database Exploits ID:1837 - Exploit for Arbitrary Command Execution - CVE-2016-6433

ID:1837 - Exploit for Arbitrary Command Execution - CVE-2016-6433

Published: March 18, 2020


Vulnerability identifier: #VU784
Vulnerability risk: High
CVE-ID: CVE-2016-6433
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:

Link to public exploit:


Vulnerability description

The vulnerability allows a remote authenticated user to execute arbitrary commands on the target system.
The weakness exists due to insufficient input validation. Sending a specially crafted parameters to the web application an authenticated attacker can access the affected system and execute arbitrary commands.
Successful exploitation of the vulnerability results in arbitrary commands execution on the vulnerable system.


Remediation

The vendor has issued a fix, available at
https://sso.cisco.com/autho/forms/CDClogin.html