Lucene search

K
ciscoCiscoCISCO-SA-20130731-CM
HistoryJul 31, 2013 - 4:00 p.m.

Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products

2013-07-3116:00:00
tools.cisco.com
11

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.005

Percentile

76.3%

Multiple Cisco content network and video delivery products contain a vulnerability
when they are configured to run in central management mode. This vulnerability could allow an authenticated but unprivileged, remote attacker to
execute arbitrary code on the affected system and on the devices managed by the affected system.

Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cm[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cm”]

Affected configurations

Vulners
Node
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscointernet_streamer_content_delivery_systemMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscovideoscape_distribution_suite_for_internet_streamingMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscovideoscape_distribution_suite_optimization_engineMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscointernet_streamer_content_delivery_systemMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscovideoscape_distribution_suite_for_internet_streamingMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscovideoscape_distribution_suite_optimization_engineMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
VendorProductVersionCPE
ciscoapplication_and_content_networking_system_softwareanycpe:2.3:a:cisco:application_and_content_networking_system_software:any:*:*:*:*:*:*:*
ciscowide_area_application_servicesanycpe:2.3:a:cisco:wide_area_application_services:any:*:*:*:*:*:*:*
ciscointernet_streamer_content_delivery_systemanycpe:2.3:a:cisco:internet_streamer_content_delivery_system:any:*:*:*:*:*:*:*
ciscoenterprise_content_delivery_systemanycpe:2.3:a:cisco:enterprise_content_delivery_system:any:*:*:*:*:*:*:*
ciscovideoscape_distribution_suite_for_internet_streaminganycpe:2.3:a:cisco:videoscape_distribution_suite_for_internet_streaming:any:*:*:*:*:*:*:*
ciscovideoscape_distribution_suite_service_brokeranycpe:2.3:a:cisco:videoscape_distribution_suite_service_broker:any:*:*:*:*:*:*:*
ciscovideoscape_distribution_suite_optimization_engineanycpe:2.3:a:cisco:videoscape_distribution_suite_optimization_engine:any:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.005

Percentile

76.3%

Related for CISCO-SA-20130731-CM