CVE-2012-6392: Input Validation
Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc79779.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6392?
CVE-2012-6392 has been classified with a high severity level due to its potential to allow remote command execution.
How does CVE-2012-6392 affect Cisco Prime LAN Management Solution?
CVE-2012-6392 affects Cisco Prime LAN Management Solution versions 4.1 to 4.2.2 by failing to properly validate authentication and authorization requests.
How do I fix CVE-2012-6392?
To fix CVE-2012-6392, upgrade Cisco Prime LAN Management Solution to a patched version provided by Cisco.
What versions of Cisco Prime LAN Management Solution are impacted by CVE-2012-6392?
CVE-2012-6392 impacts Cisco Prime LAN Management Solution versions 4.1 through 4.2.2.
Can CVE-2012-6392 lead to unauthorized access?
Yes, CVE-2012-6392 can lead to unauthorized access as it allows remote attackers to execute arbitrary commands.