CVE-2017-3801: High severity cisco Unified Computing System Director vulnerability
A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulnerability is due to improper role-based access control (RBAC) after the Developer Menu is enabled in Cisco UCS Director. An attacker could exploit this vulnerability by enabling Developer Mode for his/her user profile with an end-user profile and then adding new catalogs with arbitrary workflow items to his/her profile. An exploit could allow an attacker to perform any actions defined by these workflow items, including actions affecting other tenants. Cisco Bug IDs: CSCvb64765.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
For affected Cisco UCS Director 6.0.0.0 and 6.0.0.1 installations, ensure Developer Mode/Developer Menu is not enabled for user profiles; the vulnerability occurs when the Developer Menu is enabled and RBAC is improperly enforced after that change.
Cisco UCS Director web-based GUI Developer Mode / Developer Menu for user profile = disable - Configuration
Verify that end-user profiles do not have newly added catalogs containing arbitrary workflow items that could be executed once Developer Mode is enabled.
Cisco UCS Director web-based GUI Catalog/workflow items added to end-user profile = do not add arbitrary workflow items - Compensating control
Restrict access to Developer Mode/Developer Menu functionality in Cisco UCS Director to trusted administrators so that authenticated non-privileged users cannot enable it and add catalogs/workflow items for later execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3801?
CVE-2017-3801 is classified as a privilege escalation vulnerability.
How do I fix CVE-2017-3801?
To remediate CVE-2017-3801, update Cisco UCS Director to version 6.0.0.2 or later.
Who is affected by CVE-2017-3801?
CVE-2017-3801 affects users operating Cisco UCS Director versions 6.0.0.0 and 6.0.0.1.
What causes CVE-2017-3801?
CVE-2017-3801 is caused by improper role-based access control (RBAC) within the Cisco UCS Director web-based GUI.
Can CVE-2017-3801 be exploited remotely?
CVE-2017-3801 requires an authenticated local attacker to exploit the vulnerability.