This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cisco First view 2016-09-22
Product Cloud Services Platform 2100 Last view 2018-07-18
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:cisco:cloud_services_platform_2100:2.0.0_base:*:*:*:*:*:*:* 2
cpe:2.3:a:cisco:cloud_services_platform_2100:2.1.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.1.1:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.1.2:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.2.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.2.1:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.2.2:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:cloud_services_platform_2100:2.2(4):*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
8.8 2018-07-18 CVE-2018-0394

A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted shell access on an affected system. The vulnerability is due to insufficient input validation of parameters passed to a specific function within the user interface. An attacker could exploit this vulnerability by injecting code into a function parameter. Cisco Bug IDs: CSCvi12935.

9.9 2017-10-19 CVE-2017-12251

A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) operating remotely on an affected CSP device. The vulnerability is due to weaknesses in the generation of certain authentication mechanisms in the URL of the web console. An attacker could exploit this vulnerability by browsing to one of the hosted VMs' URLs in Cisco CSP and viewing specific patterns that control the web application's mechanisms for authentication control. An exploit could allow the attacker to access a specific VM on the CSP, which causes a complete loss of the system's confidentiality, integrity, and availability. This vulnerability affects Cisco Cloud Services Platform (CSP) 2100 running software release 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, or 2.2.2. Cisco Bug IDs: CSCve64690.

9.8 2016-09-22 CVE-2016-6374

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.

7.2 2016-09-22 CVE-2016-6373

The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.

CWE : Common Weakness Enumeration

%idName
50% (2) CWE-20 Improper Input Validation
25% (1) CWE-287 Improper Authentication
25% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...

Snort® IPS/IDS

Date Description
2016-09-22 Cisco Cloud Services Platform dnslookup command injection attempt
RuleID : 40257 - Type : SERVER-WEBAPP - Revision : 1

Nessus® Vulnerability Scanner

id Description
2016-10-13 Name: The remote network virtual services management device is affected by multiple...
File: cisco-sa-20160921-csp2100.nasl - Type: ACT_GATHER_INFO