cisco-sa-teva-os-command-W4GAO6jp: Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be able to reach the web-based management interface remotely and possess valid administrative credentials. Successful exploitation results in arbitrary operating system command execution with root privileges.
What action triggers the vulnerable behavior?
The attacker saves configuration details containing malicious values through the web-based management interface. Improper validation of this user-supplied input allows command injection.
What can be done if updates cannot be installed immediately?
No workaround is available. Cisco has released software updates that address the vulnerability.