Overview
The Cisco Prime Infrastructure version 2.2 contains two binaries with SUID root world-executable privileges, allowing any local user to execute arbitrary commands as root.
Description
CWE-276: Incorrect Default Permissions Two binaries are included in Cisco Prime version 2.2 that run as SUID root with world-executable privileges. The commands are |
Impact
A remote authenticated user may escalate privileges to root and execute arbitrary commands. |
Solution
Apply an update |
Restrict executable permissions |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| Temporal | 8.5 | E:H/RL:W/RC:C |
| Environmental | 6.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Jeremy Brown for reporting this issue.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | None |
| Date Public: | 2015-07-31 |
| Date First Published: | 2015-08-17 |
| Date Last Updated: | 2015-08-17 19:26 UTC |
| Document Revision: | 57 |