Back to list

Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability — CISCO-SA-TE-AGENTFILEWRITE-TQUW3SMU

Cisco · Cisco · CISCO-SA-TE-AGENTFILEWRITE-TQUW3SMU

ID
CISCO-SA-TE-AGENTFILEWRITE-TQUW3SMU
Date
Activity
Source
Cisco
Vendor
Cisco
Threat
medium

Summary

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system of an affected device. An attacker could exploit this vulnerability by placing a symbolic link in a specific…

Product

Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite

What to do

General, cautious steps (verify details in the official source):

  • Review exposure and plan remediation based on risk and environment.
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Related advisories