The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/74709 | third party advisory vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=38905 | vendor advisory |
http://www.securitytracker.com/id/1032359 | third party advisory vdb entry |