10
CVSSv2

CVE-2010-3036

Published: 29/10/2010 Updated: 06/11/2010
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services prior to 4.0 allow remote malicious users to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ciscoworks_common_services 3.2

cisco ciscoworks_common_services 3.3

cisco ciscoworks_common_services 3.0.5

cisco ciscoworks_common_services 3.0.6

cisco ciscoworks_common_services 3.1

cisco ciscoworks_common_services 3.1.1

cisco unified_operations_manager 2.0.2

cisco unified_operations_manager 2.0.3

cisco ciscoworks_lan_management_solution 3.0

cisco ciscoworks_lan_management_solution 3.1

cisco unified_service_monitor 2.0.1

cisco qos_policy_manager 4.0

cisco ciscoworks_lan_management_solution 3.2

cisco security_manager 3.0.2

cisco security_manager 3.2

cisco qos_policy_manager 4.0.1

cisco qos_policy_manager 4.0.2

cisco telepresence_readiness_assessment_manager 1.0

cisco unified_operations_manager 2.0.1

cisco ciscoworks_lan_management_solution 2.6

Vendor Advisories

CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator Cisco has released software updates that address this vulnerability There are no workarounds that miti ...