Cisco Security Advisory
Follow
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
A security vulnerability exists in the web-based management interface of Cisco Crosswork Network Controller. This flaw allows an authenticated, remote attacker to execute arbitrary commands. The vulnerability stems from inadequate input validation within the configuration template engine. An attacker can exploit this by submitting a specially crafted request. Successful exploitation grants the attacker the ability to run arbitrary commands on the operating system. However, this is restricted to specific file system areas where the template user possesses write permissions. Crucially, the attacker must have valid template user credentials with write access. Users with only read permissions cannot exploit this vulnerability. Cisco has already released software updates to fix this issue. Unfortunately, no workarounds are available to mitigate this vulnerability.