Cisco Application Control Engine 4710 Lets Local Users Read and Modify Files on the Target System : 8/27/2015 7:38:09 AM

Communicate with co-workers in real time. Used by Netflix, Dropbox & Salesforce. $0/unlimited users. Get started >>
From our sponsors
 

 

Vulnerability Databse
This module replaces the description field of a feed to the page it links to (in addition, it wipes out the content:encoded field), so you can get its full text.

Cisco Application Control Engine 4710 Lets Local Users Read and Modify Files on the Target System
8/27/2015 12:00:00 AM

Cisco Application Control Engine 4710 Lets Local Users Read and Modify Files on the Target System
SecurityTracker Alert ID:  1033381
SecurityTracker URL:  http://securitytracker.com/id/1033381
CVE Reference:   CVE-2015-6265   (Links to External Site)
Date:  Aug 26 2015
Impact:   Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
Vendor Confirmed:  Yes  
Version(s): ACE 4700 Series; 3.0
Description:   A vulnerability was reported in Cisco Application Control Engine. A local user can read and modify files on the target system.

A local user can exploit a flaw in the command-line interface (CLI) to view and modify files that belong to other contexts.

The vendor has assigned bug ID CSCur23662 to this vulnerability.

Impact:   A local user can read and modify files that belong to other contexts.
Solution:   No solution was available at the time of this entry.

The vendor's advisory is available at:

http://tools.cisco.com/security/center/viewAlert.x?alertId=40666

Vendor URL:  tools.cisco.com/security/center/viewAlert.x?alertId=40666 (Links to External Site)
Cause:   Not specified
Underlying OS:  

Message History:   None.

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

Diberdayakan oleh Blogger.