9
CVSSv2

CVE-2014-0679

Published: 27/02/2014 Updated: 29/07/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Cisco Prime Infrastructure 1.2 and 1.3 prior to 1.3.0.20-2, 1.4 prior to 1.4.0.45-2, and 2.0 prior to 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.

Affected Products

Vendor Product Versions
CiscoPrime Infrastructure1.2, 1.2.1, 1.3, 1.4, 1.4.1, 2.0

Vendor Advisories

A vulnerability in Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands with root-level privileges The vulnerability is due to improper validation of URL requests An attacker could exploit this vulnerability by requesting an unauthorized command via a specific URL Successful exploitation could a ...