Lucene search

K
cveCiscoCVE-2013-3443
HistoryAug 01, 2013 - 1:32 p.m.

CVE-2013-3443

2013-08-0113:32:30
CWE-20
cisco
web.nvd.nist.gov
25
cisco
waas
software
remote code execution
vulnerability
cve-2013-3443
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.092

Percentile

94.7%

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.

Affected configurations

Nvd
Node
ciscowide_area_application_servicesMatch4.0.1
OR
ciscowide_area_application_servicesMatch4.0.3
OR
ciscowide_area_application_servicesMatch4.0.5
OR
ciscowide_area_application_servicesMatch4.0.7
OR
ciscowide_area_application_servicesMatch4.0.9
OR
ciscowide_area_application_servicesMatch4.0.11
OR
ciscowide_area_application_servicesMatch4.0.13
OR
ciscowide_area_application_servicesMatch4.0.17
OR
ciscowide_area_application_servicesMatch4.0.19
OR
ciscowide_area_application_servicesMatch4.0.21
OR
ciscowide_area_application_servicesMatch4.0.23
OR
ciscowide_area_application_servicesMatch4.0.25
OR
ciscowide_area_application_servicesMatch4.0.27
Node
ciscowide_area_application_servicesMatch4.1.1
OR
ciscowide_area_application_servicesMatch4.1.1a
OR
ciscowide_area_application_servicesMatch4.1.1b
OR
ciscowide_area_application_servicesMatch4.1.1c
OR
ciscowide_area_application_servicesMatch4.1.1d
OR
ciscowide_area_application_servicesMatch4.1.3
OR
ciscowide_area_application_servicesMatch4.1.3a
OR
ciscowide_area_application_servicesMatch4.1.3b
OR
ciscowide_area_application_servicesMatch4.1.5a
OR
ciscowide_area_application_servicesMatch4.1.5b
OR
ciscowide_area_application_servicesMatch4.1.5c
OR
ciscowide_area_application_servicesMatch4.1.5d
OR
ciscowide_area_application_servicesMatch4.1.5e
OR
ciscowide_area_application_servicesMatch4.1.5f
OR
ciscowide_area_application_servicesMatch4.1.5g
OR
ciscowide_area_application_servicesMatch4.1.7
OR
ciscowide_area_application_servicesMatch4.1.7a
OR
ciscowide_area_application_servicesMatch4.1.7b
Node
ciscowide_area_application_servicesMatch4.2.1
OR
ciscowide_area_application_servicesMatch4.2.3
OR
ciscowide_area_application_servicesMatch4.2.3a
OR
ciscowide_area_application_servicesMatch4.2.3b
OR
ciscowide_area_application_servicesMatch4.2.3c
Node
ciscowide_area_application_servicesMatch4.3.1
OR
ciscowide_area_application_servicesMatch4.3.3
OR
ciscowide_area_application_servicesMatch4.3.5
OR
ciscowide_area_application_servicesMatch4.3.5a
Node
ciscowide_area_application_servicesMatch4.4.1
OR
ciscowide_area_application_servicesMatch4.4.3
OR
ciscowide_area_application_servicesMatch4.4.3a
OR
ciscowide_area_application_servicesMatch4.4.3b
OR
ciscowide_area_application_servicesMatch4.4.3c
OR
ciscowide_area_application_servicesMatch4.4.5
OR
ciscowide_area_application_servicesMatch4.4.5a
OR
ciscowide_area_application_servicesMatch4.4.5b
OR
ciscowide_area_application_servicesMatch4.4.5c
OR
ciscowide_area_application_servicesMatch4.4.5d
OR
ciscowide_area_application_servicesMatch4.4.7
Node
ciscowide_area_application_servicesMatch5.0.1
OR
ciscowide_area_application_servicesMatch5.0.3
OR
ciscowide_area_application_servicesMatch5.0.3a
OR
ciscowide_area_application_servicesMatch5.0.3c
OR
ciscowide_area_application_servicesMatch5.0.3d
Node
ciscowide_area_application_servicesMatch5.1.1
OR
ciscowide_area_application_servicesMatch5.1.1a
OR
ciscowide_area_application_servicesMatch5.1.1b
Node
ciscowide_area_application_servicesMatch5.2
VendorProductVersionCPE
ciscowide_area_application_services4.0.3cpe:/a:cisco:wide_area_application_services:4.0.3:::
ciscowide_area_application_services4.0.7cpe:/a:cisco:wide_area_application_services:4.0.7:::
ciscowide_area_application_services4.0.13cpe:/a:cisco:wide_area_application_services:4.0.13:::
ciscowide_area_application_services4.0.11cpe:/a:cisco:wide_area_application_services:4.0.11:::
ciscowide_area_application_services4.0.23cpe:/a:cisco:wide_area_application_services:4.0.23:::
ciscowide_area_application_services4.0.21cpe:/a:cisco:wide_area_application_services:4.0.21:::
ciscowide_area_application_services4.0.5cpe:/a:cisco:wide_area_application_services:4.0.5:::
ciscowide_area_application_services4.0.27cpe:/a:cisco:wide_area_application_services:4.0.27:::
ciscowide_area_application_services4.0.9cpe:/a:cisco:wide_area_application_services:4.0.9:::
ciscowide_area_application_services4.0.19cpe:/a:cisco:wide_area_application_services:4.0.19:::
Rows per page:
1-10 of 131

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.092

Percentile

94.7%