VARIoT IoT vulnerabilities database
| VAR-201706-0554 | CVE-2017-6639 | Cisco Prime Data Center Network Manager Vulnerability to access important information in the role-based access control function |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesb3p03762en_us
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: hpesb3p03762en_us
Version: 1
HPESB3P03762 rev.1 - HPE C Switch Software using Cisco Prime Data Center
Network Manager (DCNM), Remote Code Execution
NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible. The affected versions of DCNM are 10.1(1) and
10.1(2).
References:
- CVE-2017-6639
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
- HP C-series Switch Software Data Center Network Manager Version 10.1(1),
10.1(2)
BACKGROUND
CVSS Base Metrics
=================
Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector
CVE-2017-6639
10.0 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Information on CVSS is documented in
HPE Customer Notice HPSN-2008-002 here:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c01345499
RESOLUTION
There are no workarounds that address this vulnerability. Cisco has released
software updates that address this vulnerability with DCNM 10.2(1). HPE has
made the updates available to customers under contract through HPE Support
Center:
* <http://www.hpe.com/support/hpesc>
**It is essential that all HPE customers who had previously downloaded any of
the firmware and DCNM packages above download again with the updated packages
from the HPE Support Center.** All packages have been updated to include DCNM
10.2(1), and they are listed here:
* MDS 7.3(0)DY(1), released June 2017
* MDS 7.3(1)DY(1), released June 2017
* Nexus 5.2(1)N1(9b), released June 2017
HISTORY
Version:1 (rev.1) - 11 August 2017 Initial release
Third Party Security Patches: Third party security patches that are to be
installed on systems running Hewlett Packard Enterprise (HPE) software
products should be applied in accordance with the customer's patch management
policy.
Support: For issues about implementing the recommendations of this Security
Bulletin, contact normal HPE Services support channel. For other issues about
the content of this Security Bulletin, send e-mail to security-alert@hpe.com.
Report: To report a potential security vulnerability for any HPE supported
product:
Web form: https://www.hpe.com/info/report-security-vulnerability
Email: security-alert@hpe.com
Subscribe: To initiate a subscription to receive future HPE Security Bulletin
alerts via Email: http://www.hpe.com/support/Subscriber_Choice
Security Bulletin Archive: A list of recently released Security Bulletins is
available here: http://www.hpe.com/support/Security_Bulletin_Archive
Software Product Category: The Software Product Category is represented in
the title by the two characters following HPSB.
3C = 3COM
3P = 3rd Party Software
GN = HPE General Software
HF = HPE Hardware and Firmware
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PV = ProCurve
ST = Storage Software
UX = HP-UX
Copyright 2016 Hewlett Packard Enterprise
Hewlett Packard Enterprise shall not be liable for technical or editorial
errors or omissions contained herein. The information provided is provided
"as is" without warranty of any kind. To the extent permitted by law, neither
HP or its affiliates, subcontractors or suppliers will be liable for
incidental,special or consequential damages including downtime cost; lost
profits; damages relating to the procurement of substitute products or
services; or damages for loss of data, or software restoration. The
information in this document is subject to change without notice. Hewlett
Packard Enterprise and the names of Hewlett Packard Enterprise products
referenced herein are trademarks of Hewlett Packard Enterprise in the United
States and other countries. Other product and company names mentioned herein
may be trademarks of their respective owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBCAAGBQJZjL4yAAoJELXhAxt7SZaiac4IAIDr4QnvkSMG3dtIfdJm+crg
RCz+V5mdDBRzcB2PpOtwp1xoTpDYmSa7hLAsASPE3C4V2UroizRZQa0v5lx6Qpej
EVTkkLuVyNIUnN2Bg/Cm3vMNrTjwvzCeP6JJmyBcht5qJXN+TwqTO5Ie2EuUomGA
UjguaR7b3jv5AxsYymXbCA/iJDHW9hOXqWjqstSnFEJYnYVWhdqv8qTyCAaCegnG
iAa3yHYtbJHUcrPa3HGO7hkXueow9Nsnfx13Lh6GTvo0/6fSDUP9fVSEGynk+RD6
ss0SQ+IthBKWDmiwOshH2cJ9HNPkBRrmQ7OlW/9tjUDHWyTttD4/4f5pD16PzeA=
=ElxI
-----END PGP SIGNATURE-----
| VAR-201706-0582 | CVE-2017-6666 | Cisco Network Convergence System 5500 For series router Cisco IOS XR Service disruption in software (DoS) Vulnerabilities |
CVSS V2: 1.9 CVSS V3: 6.0 Severity: MEDIUM |
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition. More Information: CSCvd16665. Known Affected Releases: 6.2.11.BASE. Known Fixed Releases: 6.1.3 6.1.2 6.3.1.8i.BASE 6.2.11.8i.BASE 6.2.2.9i.BASE 6.1.32.11i.BASE 6.1.31.10i.BASE 6.1.4.3i.BASE. Vendors have confirmed this vulnerability Bug ID CSCvd16665 It is released as.Denial of service by a local attacker (DoS) There is a possibility of being put into a state. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. A denial of service vulnerability exists in Cisco IOSXR Software, which can cause a denial of service (process overload) by exploiting a memory leak vulnerability in the gRPC service.
A local attacker can exploit this issue to cause a denial-of-service condition, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCvd16665 . The forwarding component is one of the information forwarding components
| VAR-201706-0583 | CVE-2017-6667 | Cisco Context Service software development kit of dynamic JAR Vulnerability in arbitrary code execution in file update process |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server. More Information: CSCvb66730. Known Affected Releases: 2.0. Cisco Context Service SDK is prone to a remote code-execution vulnerability because it fails to properly sanitize user-supplied input.
Successful exploit allows an attacker to execute arbitrary code within the context of the user on the affected system.
This issue is being tracked by Cisco Bug ID CSCvb66730. Cisco Context Service SDK is a set of software development toolkit for Context service developed by American Cisco (Cisco). The vulnerability stems from the fact that the program does not properly filter the input submitted by the user
| VAR-201706-0584 | CVE-2017-6668 | Cisco Unified Communications Domain Manager of Web Base of GUI Vulnerabilities affected by system confidentiality |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1. Vendors have confirmed this vulnerability Bug ID CSCvc52784 and CSCvc97648 It is released as.By a remotely authenticated attacker SQL The execution of the query can affect the confidentiality of the system.
Exploiting these issues could allow an authenticated attacker to compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID's CSCvc52784 and CSCvc97648. This component features scalable, distributed, and highly available enterprise Voice over IP call processing. The Web-based GUI in CUCDM has a SQL injection vulnerability, which stems from the fact that the program does not fully verify the input submitted by the user in the HTTP request parameters
| VAR-201706-0586 | CVE-2017-6670 | Cisco Unified Communications Domain Manager of Web Base of GUI Redirected vulnerabilities |
CVSS V2: 5.8 CVSS V3: 6.1 Severity: MEDIUM |
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1. Vendors have confirmed this vulnerability Bug ID CSCvc54813 It is released as.Remote attackers can malicious users Web You may be redirected to the page.
An attacker can leverage this issue to conduct phishing attacks; other attacks are possible.
This issue is being tracked by Cisco Bug ID CSCvc54813. This component features scalable, distributed, and highly available enterprise Voice over IP call processing. The web-based GUI in CUCDM has an open redirection vulnerability, which is caused by the fact that the program does not correctly perform input validation on HTTP request parameters
| VAR-201706-0587 | CVE-2017-6671 | Cisco Email Security Appliance for Cisco AsyncOS Vulnerability in software that bypasses filters configured on devices |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter. More Information: CSCvd34632. Known Affected Releases: 10.0.1-087 9.7.1-066. Known Fixed Releases: 10.0.2-020 9.8.1-015. Vendors have confirmed this vulnerability Bug ID CSCvd34632 It is released as.A remote attacker could bypass the filters set on the device. CiscoEmailSecurityAppliance is a set of email security appliances. CiscoContentSecurityManagement is a unified email and web security management solution. An email scanning vulnerability exists in CiscoAsyncOSSoftware on CiscoEmailSecurityAppliance (ESA) devices. This vulnerability stems from incorrect authentication of emails with attachments and modified MIME headers. An unauthenticated remote attacker bypasses the configured filter.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCvd34632. AsyncOS Software is the operating system used in it
| VAR-201706-0588 | CVE-2017-6673 | Cisco FirePOWER Management Center Vulnerability in obtaining user information |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
This issue is being tracked by Cisco bug ID CSCvc10894. An attacker could exploit this vulnerability to retrieve user log files
| VAR-201706-0557 | CVE-2017-6675 | Cisco Industrial Network Director Cross-Site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases: 1.1(0.176). The system is automated through the visualization of industrial Ethernet infrastructure. A remote attacker could exploit this vulnerability to execute arbitrary HTML or script code in the context of an affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID CSCvd25405
| VAR-201706-0559 | CVE-2017-6680 | Cisco Ultra Services Framework of AutoVNF Vulnerability in creating arbitrary directories on affected systems in logging |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0.
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76652
| VAR-201706-0560 | CVE-2017-6681 | Cisco Ultra Services Framework of AutoVNF VNFStagingView Vulnerability to execute relative path traversal attack in class |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system. More Information: CSCvc76662. Known Affected Releases: 21.0.0. Vendors have confirmed this vulnerability Bug ID CSCvc76662 It is released as.A remote attacker could read important files on your system.
Successful exploits will allow attackers to obtain sensitive information. This may result in further attacks.
This issue is tracked by Cisco Bug ID CSCvc76662
| VAR-201710-1335 | CVE-2017-9377 | Barco ClickShare CSM-1 Base Unit and ClickShare CSC-1 Base Unit Command Injection Vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device. BarcoClickShareCSM-1BaseUnit and ClickShareCSC-1BaseUnit are both wireless presentation system host devices from Barco, Belgium. Multiple Barco ClickShare Base Units are prone to multiple command-injection vulnerabilities because it fails to properly sanitize user-supplied input. This may aid in further attacks
| VAR-201706-0765 | CVE-2017-9466 | TP-Link WR841N V8 Vulnerabilities related to the use of cryptographic algorithms in routers |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces. TP-Link WR841N V8 The router contains a vulnerability related to the use of cryptographic algorithms.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The TP-LinkWR841N is a SOHO wireless router. An arbitrary code execution vulnerability exists in TP-LINKWR841NV8 and earlier. An attacker can bypass the access restrictions to reset the router's authentication information (password, etc.). After exploiting this vulnerability for higher privileges, an attacker could again exploit the stack overflow vulnerability in a configuration service to execute code. TP-Link WR841N V8 is a wireless router product of China Pulian (TP-LINK) company. executable httpd is one of the executable HTTP server programs. There is a security vulnerability in executable httpd in versions earlier than TP-Link WR841N V8 TL-WR841N(UN)_V8_170210
| VAR-201706-0561 | CVE-2017-6682 | Cisco Elastic Services Controller of ConfD CLI In OS Command injection vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76). Vendors have confirmed this vulnerability Bug ID CSCvc76620 It is released as.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state.
An attacker can exploit this issue to execute arbitrary command on the affected system. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCvc76620. ConfD CLI is one of these modules
| VAR-201706-0563 | CVE-2017-6684 | Cisco Elastic Services Controller In Linux Logged in to affected systems as an admin user |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Releases: 21.0.0.
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76651
| VAR-201706-0565 | CVE-2017-6686 | Cisco Ultra Services Framework Element Manager Admin in or oper Vulnerability logged in as a user |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76699. Known Affected Releases: 21.0.0. CiscoUltraServicesFramework is an intelligent online service payment platform from Cisco. ElementManager is one of the software used to manage server switches. A security vulnerability exists in CiscoUltraServicesFrameworkElementManager.
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76699
| VAR-201706-0566 | CVE-2017-6687 | Cisco Ultra Services Framework Element Manager Vulnerable to logging into the system using default credentials |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Password Vulnerability. More Information: CSCvc76695. Known Affected Releases: 21.0.0. CiscoUltraServicesFramework is an intelligent online service payment platform from Cisco. ElementManager is one of the software used to manage server switches. A security vulnerability exists in CiscoUltraServicesFrameworkElementManager. A remote attacker could exploit the vulnerability to log in to an affected device. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCvc76695
| VAR-201706-0567 | CVE-2017-6688 | Cisco Elastic Services Controller In Linux root Vulnerability logged in as a user |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information: CSCvc76631. Known Affected Releases: 2.2(9.76).
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76631
| VAR-201706-0568 | CVE-2017-6689 | Cisco Elastic Services Controller of ConfD CLI Login vulnerability as an administrator |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc76661. Known Affected Releases: 2.2(9.76).
An attacker can exploit this issue to bypass the security mechanism and gain unauthorized access. This may lead to further attacks.
This issue is tracked by Cisco Bug ID CSCvc76661. ConfD CLI is one of these modules
| VAR-201706-0569 | CVE-2017-6690 | Cisco ASR 5000 Series Aggregated Services Router Run on StarOS Vulnerabilities in arbitrary file overwriting in file check operation |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary files on an affected system. More Information: CSCvd73726. Known Affected Releases: 21.0.v0.65839 21.3.M0.67005. Known Fixed Releases: 21.4.A0.67087 21.4.A0.67079 21.4.A0.67013 21.3.M0.67084 21.3.M0.67077 21.3.M0.66994 21.3.J0.66993 21.1.v0.67082 21.1.V0.67083. Vendors report this vulnerability CSCvd73726 Published as.Arbitrary files could be overwritten or modified by a remotely authenticated attacker. CiscoStarOS is a set of operating systems operated by Cisco Systems Inc. in a series of routers such as 5000. CiscoStarOS has a remote security bypass vulnerability that can be exploited by remote authentication attackers to modify arbitrary files. The vulnerability stems from a failure of the program to fully validate the input.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCvd73726
| VAR-201706-0570 | CVE-2017-6691 | Cisco Elastic Services Controller of ConfD CLI Vulnerability in accessing critical information |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information on an affected system. More Information: CSCvd29403. Known Affected Releases: 2.3(2).
Successful exploits will allow attackers to obtain sensitive information. This may result in further attacks.
This issue is tracked by Cisco Bug ID CSCvd29403. ConfD CLI is one of these modules