7.8
CVSSv2

CVE-2010-0144

Published: 11/02/2010 Updated: 26/02/2010
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x prior to 6.2.9.1 and 6.5.x prior to 6.5.2, and the IronPort PostX MAP prior to 6.2.9.1, allows remote malicious users to read arbitrary files via unknown vectors, aka IronPort Bug 65922.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ironport encryption appliance 6.2.4.1

cisco ironport encryption appliance 6.2.7.5

cisco ironport encryption appliance 6.2.7

cisco ironport postx 6.2.2.2

cisco ironport encryption appliance 6.2.7.3

cisco ironport encryption appliance 6.2.5

cisco ironport encryption appliance 6.5.0.1

cisco ironport postx 6.2.1

cisco ironport encryption appliance 6.2.7.4

cisco ironport encryption appliance 6.2.6

cisco ironport postx 6.2.2

cisco ironport postx 6.2.2.1

cisco ironport encryption appliance 6.2.7.1

cisco ironport encryption appliance 6.2.7.2

cisco ironport encryption appliance 6.2.4

cisco ironport encryption appliance 6.2.7.6

cisco ironport encryption appliance 6.5

Vendor Advisories

Cisco IronPort Encryption Appliance devices contain two vulnerabilities that allow remote, unauthenticated access to any file on the device and one vulnerability that allows remote, unauthenticated users to execute arbitrary code with elevated privileges There are workarounds available to mitigate these vulnerabilities This advisory is posted at ...