The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6631 | vdb entry |
http://www.osvdb.org/1848 | vdb entry |
http://www.securityfocus.com/bid/2806 | vdb entry |
http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtml | patch vendor advisory |