Executive Summary

Summary
Title CiscoWorks Common Services Arbitrary Command Execution Vulnerability
Informations
Name cisco-sa-20111019-cs First vendor Publication N/A
Vendor Cisco Last vendor Modification 2011-10-19
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:S/C:C/I:C/A:C)
Cvss Base Score 9 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

CiscoWorks Common Services for Microsoft Windows contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands on the affected system with the privileges of a system administrator.

Cisco has released free software updates that address this vulnerability.

There are no workarounds that mitigate this vulnerability.

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-94 Failure to Control Generation of Code ('Code Injection')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 20
Os 1

Open Source Vulnerability Database (OSVDB)

Id Description
76565 CiscoWorks Common Services Home Page Component Unspecified URI Shell Command ...

Information Assurance Vulnerability Management (IAVM)

Date Description
2011-10-27 IAVM : 2011-A-0148 - CiscoWorks Common Services Remote Code Execution Vulnerability
Severity : Category I - VMSKEY : V0030544

Nessus® Vulnerability Scanner

Date Description
2013-08-19 Name : The remote host has a web application installed that is affected by an arbitr...
File : ciscoworks_common_services_20111019.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 10:22:02
  • Multiple Updates
2013-11-11 12:37:30
  • Multiple Updates