Guest

Preview Tool

Cisco Bug: CSCte90315 - Command Injection and Unauthorized File Access via SAM CLI

Last Modified

Aug 06, 2018

Products (1)

  • Cisco Unified Computing System

Known Affected Releases

1.2(0.9)

Description (partial)

Symptoms:
A vulnerability exists in affected versions of Unified Computing System software which could allow an authenticated local attacker to execute arbitrary 
commands or gain unauthorized access to arbitrary files on the underlying operating system. A successful exploit would allow an attacker to gain 
elevated privileges on the underlying operating system.

Conditions:
Devices running affected versions of Unified Computing System software are vulnerable.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.