Cisco Products Remote Code Execution Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
A vulnerability has been identified in the Apache Struts 2 component of multiple Cisco products.
The vulnerability is due to insufficient sanitization on user-supplied input in the XWorks component of the affected software. The component uses the ParameterInterceptors directive to parse the Object-Graph Navigation Language (OGNL) expressions that are implemented via a whitelist feature. By sending crafted requests that contain OGNL expressions to an affected system, it could allow an attacker to execute arbitrary code.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Cisco Business Edition 3000 Series
- Cisco Identity Services Engine (ISE)
- Cisco Media Experience Engine (MXE) 3500 Series
- Cisco Unified Contact Center Enterprise (Cisco Unified CCE)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply software updates from the vendor or contact the maintenance providers.
Vulnerability Identifier
Source
Related Link
Share with