Lucene search

K
cveCiscoCVE-2013-5554
HistoryNov 08, 2013 - 4:47 a.m.

CVE-2013-5554

2013-11-0804:47:23
CWE-22
cisco
web.nvd.nist.gov
26
cve-2013-5554
directory traversal
web management interface
cisco
waas mobile
remote attack
vulnerability
security
bug id cscuh69773
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.039

Percentile

92.1%

Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773.

Affected configurations

Nvd
Node
ciscowide_area_application_services_mobileRange3.5.4
OR
ciscowide_area_application_services_mobileMatch3.3.1
OR
ciscowide_area_application_services_mobileMatch3.3.4
OR
ciscowide_area_application_services_mobileMatch3.4
OR
ciscowide_area_application_services_mobileMatch3.4.1
OR
ciscowide_area_application_services_mobileMatch3.4.2
OR
ciscowide_area_application_services_mobileMatch3.5.0
OR
ciscowide_area_application_services_mobileMatch3.5.1
OR
ciscowide_area_application_services_mobileMatch3.5.2
OR
ciscowide_area_application_services_mobileMatch3.5.3
VendorProductVersionCPE
ciscowide_area_application_services_mobile*cpe:2.3:a:cisco:wide_area_application_services_mobile:*:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.3.1cpe:2.3:a:cisco:wide_area_application_services_mobile:3.3.1:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.3.4cpe:2.3:a:cisco:wide_area_application_services_mobile:3.3.4:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.4cpe:2.3:a:cisco:wide_area_application_services_mobile:3.4:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.4.1cpe:2.3:a:cisco:wide_area_application_services_mobile:3.4.1:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.4.2cpe:2.3:a:cisco:wide_area_application_services_mobile:3.4.2:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.5.0cpe:2.3:a:cisco:wide_area_application_services_mobile:3.5.0:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.5.1cpe:2.3:a:cisco:wide_area_application_services_mobile:3.5.1:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.5.2cpe:2.3:a:cisco:wide_area_application_services_mobile:3.5.2:*:*:*:*:*:*:*
ciscowide_area_application_services_mobile3.5.3cpe:2.3:a:cisco:wide_area_application_services_mobile:3.5.3:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.039

Percentile

92.1%