CVE-2024-20277

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands and elevate privileges to root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:thousandeyes_enterprise_agent:*:*:*:*:*:*:*:*

History

02 Feb 2024, 16:15

Type Values Removed Values Added
CWE CWE-78

29 Jan 2024, 17:32

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thouseyes-privesc-DmzHG3Qv - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thouseyes-privesc-DmzHG3Qv - Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 8.0
CWE NVD-CWE-noinfo
First Time Cisco
Cisco thousandeyes Enterprise Agent
Summary
  • (es) Una vulnerabilidad en la interfaz de administración basada en web de Cisco ThousandEyes Enterprise Agent, tipo de instalación de dispositivo virtual, podría permitir que un atacante remoto autenticado realice una inyección de comando y eleve los privilegios a root. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario para la interfaz web. Un atacante podría aprovechar esta vulnerabilidad enviando un paquete HTTP manipulado al dispositivo afectado. Una explotación exitosa podría permitir al atacante ejecutar comandos arbitrarios y elevar privilegios a root.
CPE cpe:2.3:a:cisco:thousandeyes_enterprise_agent:*:*:*:*:*:*:*:*

17 Jan 2024, 17:35

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-17 17:15

Updated : 2024-02-02 16:15


NVD link : CVE-2024-20277

Mitre link : CVE-2024-20277

CVE.ORG link : CVE-2024-20277


JSON object : View

Products Affected

cisco

  • thousandeyes_enterprise_agent
CWE
NVD-CWE-noinfo CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')