Vulnerability Name: CVE-2013-1125 (CCN-82160) Assigned: 2013-02-15 Published: 2013-02-15 Updated: 2013-02-20 Summary: The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services Manager does not properly validate input, which allows local users to obtain root privileges via unspecified vectors, aka Bug IDs CSCue46001, CSCud95790, CSCue46021, CSCue46025, CSCue46023, CSCue46058, CSCue46013, CSCue46031, CSCue46035, and CSCue46042. CVSS v3 Severity: 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C )5.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-20 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2013-1125 Source: CCN Type: SA52268Cisco Multiple Products CLI Root Shell Access Privilege Escalation Vulnerability Source: CCN Type: Cisco Security NoticeMultiple Cisco Product Root Shell Access Vulnerability Source: CISCO Type: UNKNOWN20130215 Multiple Cisco Product Root Shell Access Vulnerability Source: XF Type: UNKNOWNcisco-command-line-priv-esc(82160) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:application_networking_manager:-:*:*:*:*:*:*:* OR cpe:/a:cisco:context_directory_agent:-:*:*:*:*:*:*:* OR cpe:/a:cisco:identity_services_engine_software:-:*:*:*:*:*:*:* OR cpe:/a:cisco:network_services_manager:-:*:*:*:*:*:*:* OR cpe:/a:cisco:prime_collaboration:-:*:*:*:*:*:*:* OR cpe:/a:cisco:prime_lan_management_solution:-:*:*:*:*:*:*:* OR cpe:/a:cisco:prime_network_control_system:-:*:*:*:*:*:*:* OR cpe:/a:cisco:quad:-:*:*:*:*:*:*:* OR cpe:/a:cisco:secure_access_control_system:-:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_provisioning_manager:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:cisco:application_networking_manager:1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:application_networking_manager:1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:application_networking_manager:2.0:*:*:*:*:*:*:* OR cpe:/a:cisco:prime_lan_management_solution:4.2:*:*:*:*:*:*:* OR cpe:/a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:identity_services_engine_software:1.0.4:*:*:*:*:*:*:* OR cpe:/a:cisco:identity_services_engine_software:1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:secure_access_control_system:-:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco application networking manager -
cisco context directory agent -
cisco identity services engine software -
cisco network services manager -
cisco prime collaboration -
cisco prime lan management solution -
cisco prime network control system -
cisco quad -
cisco secure access control system -
cisco unified provisioning manager -
cisco application networking manager 1.2
cisco application networking manager 1.1
cisco application networking manager 2.0
cisco prime lan management solution 4.2
cisco identity services engine software 1.0
cisco identity services engine software 1.0.4
cisco identity services engine software 1.1
cisco secure access control system -