Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20277

Опубликовано: 17 янв. 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 8
EPSS Низкий

Описание

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands and elevate privileges to root.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:thousandeyes_enterprise_agent:*:*:*:*:*:*:*:*
Версия до 0.233.2 (исключая)

EPSS

Процентиль: 39%
0.00175
Низкий

6.8 Medium

CVSS3

8 High

CVSS3

Дефекты

CWE-78
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.8
github
около 2 лет назад

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands and elevate privileges to root.

CVSS3: 8
fstec
около 2 лет назад

Уязвимость веб-интерфейса управления программного обеспечения для анализа сетей Cisco ThousandEyes Enterprise Agent, позволяющая нарушителю выполнить произвольные команды и повысить свои привилегии до уровня root

EPSS

Процентиль: 39%
0.00175
Низкий

6.8 Medium

CVSS3

8 High

CVSS3

Дефекты

CWE-78
NVD-CWE-noinfo