6.8
CVSSv2

CVE-2010-0146

Published: 23/02/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated malicious user to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated malicious user to execute SQL statements that can cause instability of the product or changes in the configuration. Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated exploitation could result in a sustained DoS condition. These vulnerabilities are independent of each other. Cisco has released software updates that address these vulnerabilities. This advisory is posted at tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100217-csa.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco security agent 6.0

Vendor Advisories

The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center Successful exploitation of the ...