The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1032999 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=39990 | vendor advisory |
http://www.securityfocus.com/bid/75953 | vdb entry |