The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2016-02-26T02:00:00
Updated: 2016-12-02T20:57:01
Reserved: 2016-01-04T00:00:00
Link: CVE-2016-1297
JSON object: View
NVD Information
Status : Modified
Published: 2016-02-26T05:59:00.130
Modified: 2016-12-06T03:06:34.463
Link: CVE-2016-1297
JSON object: View
Redhat Information
No data.
CWE