IT

Tracker / CVE-2013-1196

CVE-2013-1196

Medium 6.8

The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime Data Center Network Manager (DCNM), and Quad does not properly validate input, which allows local users to obtain root privileges via unspecified vectors, aka Bug IDs CSCug29384, CSCug13866, CSCug29400, CSCug29406, CSCug29411, CSCug29413, CSCug29416, CSCug29418, CSCug29422, CSCug29425, and CSCug29426, a different issue than CVE-2013-1125.

Affected products and versions

cisco application_networking_manager
cisco context_directory_agent
cisco identity_services_engine_software
cisco network_services_manager
cisco prime_collaboration
cisco prime_data_center_network_manager
cisco prime_lan_management_solution
cisco prime_network_control_system
cisco quad
cisco secure_access_control_system
cisco unified_provisioning_manager

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References