The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.
References
Configurations
Information
Published : 2016-09-22 15:59
Updated : 2017-07-29 18:29
NVD link : CVE-2016-6373
Mitre link : CVE-2016-6373
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
cisco
- cloud_services_platform_2100