Cisco Bug: CSCup05998 - Arbitrary command execution vulnerability in rack CIMCs
Jun 29, 2018
- Cisco Unified Computing System
Known Affected Releases
Symptom: Cisco Integrated Management Controller (CiMC) contains a vulnerability that could allow an authenticated, local attacker to gain shell-level access to the affected device. Conditions: The vulnerability is due to improper input validation in the map-nfs command. An attacker could exploit this vulnerability by sending a crafted command in the command-line interface. Attacker must first be authenticated to the CiMC to execute the attack.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases