Cisco Wireless Control System Discloses Files to Remote Authenticated Users
|
|
SecurityTracker Alert ID: 1027011 |
|
SecurityTracker URL: http://securitytracker.com/id/1027011
|
|
CVE Reference:
CVE-2011-4014
(Links to External Site)
|
Date: May 3 2012
|
Impact:
Disclosure of system information, Disclosure of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 7.0 prior to 7.0.230.0
|
Description:
A vulnerability was reported in Cisco Wireless Control System. A remote authenticated user can view arbitrary files in a certain directory on the target system.
A remote authenticated user can exploit a flaw in the TAC Case Attachment tool to view arbitrary files in the 'webnms/Temp/' directory.
Cisco has assigned Bug ID CSCtq86807 to this vulnerability.
|
Impact:
A remote authenticated user can view arbitrary files in a certain directory on the target system.
|
Solution:
The vendor has issued a fix (7.0.230.0).
The vendor's advisory is available at:
http://www.cisco.com/en/US/docs/wireless/wcs/release/notes/WCS_RN7_0_230.html
|
Vendor URL: www.cisco.com/en/US/docs/wireless/wcs/release/notes/WCS_RN7_0_230.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|