Vulnerability Bulletins

Cisco Configuration Assistant Request Processing Unauthorized Access Vulnerability

   
Affected software Cisco
 
A vulnerability in Cisco Configuration Assistant (CCA) could allow an unauthenticated, remote attacker to access sensitive file systems and administrative endpoints without user authentication.The vulnerability is due to lack of controller mechanisms and input validation checks. An attacker could exploit this vulnerability by running GET queries to the administrative endpoints of the Cloud Network Automation Provisioner (CNAP) Application Programming Interface (API), providing access to other

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160630-cca?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Configuration%20Assistant%20Request%20Processing%20Unauthorized%20Acce