A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Releases: 4.2(2.1)PP1 4.2(3.0)PP6 4.3(0.0)PP4 4.3(1.0)PP2. Known Fixed Releases: 4.3(2).
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prime_network | Cisco | 4.2(2.1)pp1 (including) | 4.2(2.1)pp1 (including) |
Prime_network | Cisco | 4.2(3.0)pp6 (including) | 4.2(3.0)pp6 (including) |
Prime_network | Cisco | 4.3(0.0)pp4 (including) | 4.3(0.0)pp4 (including) |
Prime_network | Cisco | 4.3(1.0)pp2 (including) | 4.3(1.0)pp2 (including) |