Cisco FireSIGHT System Software Arbitrary Code Execution Vulnerability
The vulnerability is due to improper handling of modified backup configuration files. An attacker could exploit this vulnerability by modifying certain components within the backup system files. An exploit could allow the attacker to run arbitrary code as a root user on the affected appliance.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2uqbpO0
The vulnerability is due to improper handling of modified backup configuration files. An attacker could exploit this vulnerability by modifying certain components within the backup system files. An exploit could allow the attacker to run arbitrary code as a root user on the affected appliance.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2uqbpO0
Security Impact Rating: Medium
CVE: CVE-2017-6735
from Cisco Security Advisory http://ift.tt/2uqbpO0