Описание
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
EPSS
10 Critical
CVSS3
Дефекты
Связанные уязвимости
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Уязвимость системы аутентификации программного средства администрирования лицензий Cisco Smart Software Manager On-Prem, связанная с отсутствием необходимой проверки при изменении пароля, позволяющая нарушителю получить доступ к веб-интерфейсу администрирования
EPSS
10 Critical
CVSS3