10
CVSSv2

CVE-2012-5417

Published: 02/11/2012 Updated: 26/02/2013
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cisco Prime Data Center Network Manager (DCNM) prior to 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote malicious users to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime data center network manager 5.2\\(2c\\)

cisco prime data center network manager 5.2\\(2b\\)

cisco prime data center network manager 5.0\\(2\\)

cisco prime data center network manager 4.2\\(3\\)

cisco prime data center network manager 6.1\\(1b\\)

cisco prime data center network manager 5.1\\(3u\\)

cisco prime data center network manager 5.1\\(2\\)

cisco prime data center network manager 4.1\\(3\\)

cisco prime data center network manager 4.1\\(2\\)

cisco prime data center network manager 5.2\\(2a\\)

cisco prime data center network manager 5.2\\(2\\)

cisco prime data center network manager 4.2\\(1\\)

cisco prime data center network manager 4.1\\(5\\)

cisco prime data center network manager 4.1\\(4\\)

cisco prime data center network manager 6.1\\(1a\\)

cisco prime data center network manager 5.2\\(2e\\)

cisco prime data center network manager 5.1\\(1\\)

cisco prime data center network manager 5.0\\(3\\)

Vendor Advisories

Cisco Prime Data Center Network Manager (DCNM) contains a remote command execution vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands on the computer that is running the Cisco Prime DCNM application Cisco has released software updates that address this vulnerability This advisory is available at the ...