CVE-2014-0679
published 2014-02-27CVE-2014-0679: Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute…
PriorityP353critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.11%
79.6th percentile
Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure Command Execution Vulnerability
vendor_cisco·2014-02-26·CVSS 9.0
CVE-2014-0679 [CRITICAL] CWE-78 Cisco Prime Infrastructure Command Execution Vulnerability
Cisco Prime Infrastructure Command Execution Vulnerability
A vulnerability in Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands with root-level privileges.
The vulnerability is due to improper validation of URL requests. An attacker could exploit this vulnerability by requesting an unauthorized command via a specific URL. Successful exploitation could allow an authenticated attacker to execute system commands with root-level privileges.
Cisco has released software updates that address this vulnerability. A software patch that addresses this vulnerability in all affected versions is also available. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.ci
Cisco
Cisco Prime Infrastructure Command Execution Vulnerability
vendor_cisco
CVE-2014-0679 Cisco Prime Infrastructure Command Execution Vulnerability
CVE-2014-0679: Cisco Prime Infrastructure Command Execution Vulnerability
A vulnerability in Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands with root -level privileges. The vulnerability is due to improper validation of URL requests. An attacker could exploit this vulnerability by requesting an unauthorized command via a specific URL. Successful exploitation could allow an authenticated attacker to execute system commands with root -level privileges. Cisco has released software updates that address this vulnerability. A software patch that addresses this vulnerability in all affected versions is also available.
CWE: CWE-78, CWE-78
Bug IDs: CSCum71308, CSCum71308, CSCum71308, CSCum71308, CSCum71308
GHSA
GHSA-6xc4-2r77-272c: Cisco Prime Infrastructure 1
ghsa_unreviewed·2022-05-14
CVE-2014-0679 [HIGH] CWE-20 GHSA-6xc4-2r77-272c: Cisco Prime Infrastructure 1
Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-27
Published