CVE-2017-6616
published 2017-04-20CVE-2017-6616: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary…
PriorityP261high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.24%
90.0th percentile
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system. Cisco Bug IDs: CSCvd14578.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | integrated_management_controller | — | — |
| cisco | integrated_management_controller_supervisor | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2build0.18.04.1 | 2.3.0-2build0.18.04.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request to the Cisco IMC web-based GUI; monitor for anomalous or malformed HTTP requests targeting the IMC web interface that may carry unsanitized user-supplied values ↗
- →Successful exploitation results in system command execution with root-level privileges from the IMC web GUI process; alert on unexpected privileged process spawning from the IMC web server ↗
- →Track Cisco Bug IDs CSCvd14578, CSCve48833, and CSCvg31284 for patch/signature updates related to this vulnerability ↗
- ·NVD describes the vulnerability as requiring authentication, while the Cisco advisory describes it as exploitable by an unauthenticated attacker — defenders should treat the attack surface as unauthenticated (no-auth required) for conservative detection and patching posture ↗
- ·The vulnerability is confirmed in Cisco IMC version 3.0(1c); ensure all IMC firmware versions are assessed against the full list of affected releases in the Cisco advisory ↗
- ·There are no workarounds available; patching is the only mitigation ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj7q-5hj5-43hf: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3
ghsa_unreviewed·2022-05-13
CVE-2017-6616 [HIGH] CWE-20 GHSA-wj7q-5hj5-43hf: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system. Cisco Bug IDs: CSCvd14578.
OSV
openjpeg2 vulnerabilities
osv·2019-08-21·CVSS 9.8
CVE-2017-17480 openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain PGX files. An
attacker could possibly use this issue to cause a denial of service or possibly
remote code execution. (CVE-2017-17480)
It was discovered that OpenJPEG incorrectly handled certain files. An attacker
could possibly use this issue to cause a denial of service. (CVE-2018-14423)
It was discovered that OpenJPEG incorrectly handled certain PNM files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-18088)
It was discovered that OpenJPEG incorrectly handled certain BMP files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-5785, CVE-2018-6616)
Cisco
Cisco Integrated Management Controller Remote Code Execution Vulnerability
vendor_cisco·2017-04-19·CVSS 9.8
CVE-2017-6616 [CRITICAL] CWE-20 Cisco Integrated Management Controller Remote Code Execution Vulnerability
Cisco Integrated Management Controller Remote Code Execution Vulnerability
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to perform unauthorized remote command execution on the affected device.
The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. Successful exploitation could allow an unauthenticated attacker to execute system commands with root-level privileges.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.
Cisco
Cisco Integrated Management Controller Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6616 Cisco Integrated Management Controller Remote Code Execution Vulnerability
CVE-2017-6616: Cisco Integrated Management Controller Remote Code Execution Vulnerability
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to perform unauthorized remote command execution on the affected device. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. Successful exploitation could allow an unauthenticated attacker to execute system commands with root -level privileges. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvd14578, CSCve48833, CSCvg31284, CSCvg31284, CSCve48833
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-04-20
Published