Описание
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.
Ссылки
- PatchVendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:cisco:resource_manager:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:resource_manager:1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:resource_manager_essentials:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:resource_manager_essentials:2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:resource_manager_essentials:2.2:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:a:cisco:ciscoworks_common_management_foundation:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_management_foundation:2.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ciscoworks_cd1:1st:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ciscoworks_cd1:2nd:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ciscoworks_cd1:3rd:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ciscoworks_cd1:4th:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ciscoworks_cd1:5th:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00382
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.
EPSS
Процентиль: 59%
0.00382
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other