A local flaw in Cisco Spaces Connector lets someone already logged in as spacesadmin run crafted CLI commands to gain full root control of the underlying operating system.
Posts tagged: Cisco
Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability
An admin with valid CommPilot credentials can plant script in the BroadWorks management interface that runs in another admin’s browser session when they view the affected page.
Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability
Cisco Unified Intelligence Center’s web management interface fails to validate certain HTTP requests properly, letting an unauthenticated remote attacker force the device to send arbitrary network requests on its behalf.
Cisco Identity Services Engine Authenticated Remote Code Execution and Authorization
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to issue commands on the underlying …
Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability
An authenticated but low-privileged user can send a crafted request to a Prime Infrastructure or EPNM REST API to pull data out of backend database tables via blind SQL injection.
Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
An authenticated attacker holding at least Report Designer access to Cisco Unified Intelligence Center can upload arbitrary files through the web management interface and potentially escalate to root.
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Three maximum-severity flaws let anyone reach Cisco ISE’s APIs without logging in and run commands as root, with one variant also allowing arbitrary file uploads into privileged directories.
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
Flaws in the SNMP subsystem of Cisco IOS and IOS XE let anyone with a read-only community string or valid SNMPv3 credentials send a crafted packet to execute code or reload the device.