Vulnerability Name:

CVE-2013-1125 (CCN-82160)

Assigned:2013-02-15
Published:2013-02-15
Updated:2013-02-20
Summary:The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services Manager does not properly validate input, which allows local users to obtain root privileges via unspecified vectors, aka Bug IDs CSCue46001, CSCud95790, CSCue46021, CSCue46025, CSCue46023, CSCue46058, CSCue46013, CSCue46031, CSCue46035, and CSCue46042.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
5.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2013-1125

Source: CCN
Type: SA52268
Cisco Multiple Products CLI Root Shell Access Privilege Escalation Vulnerability

Source: CCN
Type: Cisco Security Notice
Multiple Cisco Product Root Shell Access Vulnerability

Source: CISCO
Type: UNKNOWN
20130215 Multiple Cisco Product Root Shell Access Vulnerability

Source: XF
Type: UNKNOWN
cisco-command-line-priv-esc(82160)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cisco:application_networking_manager:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:context_directory_agent:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:identity_services_engine_software:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:network_services_manager:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:prime_collaboration:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:prime_lan_management_solution:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:prime_network_control_system:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:quad:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:secure_access_control_system:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_provisioning_manager:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:cisco:application_networking_manager:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:application_networking_manager:1.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:application_networking_manager:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:prime_lan_management_solution:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:identity_services_engine_software:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:identity_services_engine_software:1.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:secure_access_control_system:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco application networking manager -
    cisco context directory agent -
    cisco identity services engine software -
    cisco network services manager -
    cisco prime collaboration -
    cisco prime lan management solution -
    cisco prime network control system -
    cisco quad -
    cisco secure access control system -
    cisco unified provisioning manager -
    cisco application networking manager 1.2
    cisco application networking manager 1.1
    cisco application networking manager 2.0
    cisco prime lan management solution 4.2
    cisco identity services engine software 1.0
    cisco identity services engine software 1.0.4
    cisco identity services engine software 1.1
    cisco secure access control system -