CVE Database
/

CVE-2017-3801

Back to search

CVE-2017-3801

Published: Feb 15, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulnerability is due to improper role-based access control (RBAC) after the Developer Menu is enabled in Cisco UCS Director. An attacker could exploit this vulnerability by enabling Developer Mode for his/her user profile with an end-user profile and then adding new catalogs with arbitrary workflow items to his/her profile. An exploit could allow an attacker to perform any actions defined by these workflow items, including actions affecting other tenants. Cisco Bug IDs: CSCvb64765.

VendorProductVersions

n/a

Cisco UCS Director versions 6.0.0.0 and 6.0.0.1

affected
Cisco UCS Director versions 6.0.0.0 and 6.0.0.1

Weaknesses (CWE)

References

1037830
vdb-entry
x_refsource_SECTRACK
96235
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now