cisco-sa-cisco-prime-priv-esc-HyhwdzBA: Cisco Prime License Manager Privilege Escalation Vulnerability
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-prime-priv-esc-HyhwdzBA
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-cisco-prime-priv-esc-HyhwdzBA?
The cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability is rated as critical due to the potential for unauthorized remote access.
How do I fix cisco-sa-cisco-prime-priv-esc-HyhwdzBA?
To fix the cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability, users should update to the latest version of Cisco Prime License Manager that contains the security patch.
What causes the cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability?
The cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability is caused by insufficient validation of user input in the web management interface.
Can cisco-sa-cisco-prime-priv-esc-HyhwdzBA be exploited remotely?
Yes, the cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability can be exploited by an unauthenticated remote attacker.
What software is affected by cisco-sa-cisco-prime-priv-esc-HyhwdzBA?
The cisco-sa-cisco-prime-priv-esc-HyhwdzBA vulnerability affects the Cisco Prime License Manager software.