Cisco Clean Access 3.5.5 and previous versions on the Secure Smart Manager allows remote malicious users to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco network admission control manager and server system software 3.3 |
||
cisco network admission control manager and server system software 3.3.1 |
||
cisco network admission control manager and server system software 3.3.9 |
||
cisco network admission control manager and server system software 3.4 |
||
cisco network admission control manager and server system software 3.5.1 |
||
cisco network admission control manager and server system software 3.5.2 |
||
cisco network admission control manager and server system software 3.3.7 |
||
cisco network admission control manager and server system software 3.3.8 |
||
cisco network admission control manager and server system software 3.4.5 |
||
cisco network admission control manager and server system software 3.5 |
||
cisco network admission control manager and server system software 3.3.2 |
||
cisco network admission control manager and server system software 3.3.3 |
||
cisco network admission control manager and server system software 3.4.1 |
||
cisco network admission control manager and server system software 3.4.2 |
||
cisco network admission control manager and server system software 3.5.3 |
||
cisco network admission control manager and server system software 3.5.4 |
||
cisco network admission control manager and server system software 3.3.4 |
||
cisco network admission control manager and server system software 3.3.5 |
||
cisco network admission control manager and server system software 3.3.6 |
||
cisco network admission control manager and server system software 3.4.3 |
||
cisco network admission control manager and server system software 3.4.4 |
||
cisco network admission control manager and server system software 3.5.5 |