Vulnerabilità · 181 giorni fa
Cisco Smart Software Manager On-Prem (SSM On-Prem) presenta due vulnerabilità distinte. Una consente agli utenti autenticati con ruoli System User di estrarre le credenziali di sessione tramite l'interfaccia web e di eseguire un'escalation a privilegi amministrativi. L'altra espone un servizio API interno che gli attaccanti non autenticati possono sfruttare per eseguire comandi arbitrari come root sul sistema host.
1 fonte che coprono questa storia
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
Cisco Security Advisory: Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system.
Part of the PlainSec briefing for 2026-04-02