It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the .debug_command.config file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the /api/appInternals/1.0/agent/configuration API to map the corresponding ID to a command to be executed.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Steelcentral_appinternals_dynamic_sampling_agent | Riverbed | 11.0.0 (including) | 11.8.8 (excluding) |
Steelcentral_appinternals_dynamic_sampling_agent | Riverbed | 12.0.0 (including) | 12.13.0 (excluding) |
Steelcentral_appinternals_dynamic_sampling_agent | Riverbed | 10.0.0 (including) | 10.0.0 (including) |