Boletines de Vulnerabilidades

Cisco Secure Network Analytics Remote Code Execution Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system. This vulnerability is due to insufficient user input validation by the web-based management interface of the affected software. An attacker could exploit this vulnerability by injecting arbitrary commands in the web-based management

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Secure%20Network%20Analytics%20Remote%20Code%20Execution%20Vulnerability&vs_k=1

Identificadores estándar

Propiedad Valor
CVE CVE-2022-20797.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2023-03-29

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT