The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/45355 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/68738 | vdb entry |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml | vendor advisory |
http://securitytracker.com/id?1025810 | vdb entry |
http://www.securityfocus.com/bid/48810 | vdb entry |