Vulnerability Bulletins |
Cisco ACE 4710 Application Control Engine Command Injection Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in the Device Manager GUI of the Cisco ACE 4710 Application Control Engine could allow an authenticated, remote attacker to execute any command-line interface (CLI) command on the ACE with admin user privileges. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by crafting a malicious HTTP POST request with injected CLI commands inside the value of a POST parameter value. An exploit could allow the attacker More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160224-ace?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20ACE%204710%20Application%20Control%20Engine%20Command%20Injection%20Vu |
|






