Lucene search

K
ciscoCiscoCISCO-SA-20130731-WAASCM
HistoryJul 31, 2013 - 4:00 p.m.

Cisco WAAS Central Manager Remote Code Execution Vulnerability

2013-07-3116:00:00
tools.cisco.com
15

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.092

Percentile

94.7%

Cisco Wide Area Application Services (WAAS) when configured as Central Manager (CM), contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the affected system.

Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-waascm [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-waascm”]

Affected configurations

Vulners
Node
ciscowide_area_application_servicesMatchany
OR
ciscowide_area_application_servicesMatchany
VendorProductVersionCPE
ciscowide_area_application_servicesanycpe:2.3:a:cisco:wide_area_application_services:any:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.092

Percentile

94.7%

Related for CISCO-SA-20130731-WAASCM