7.5
CVSSv2

CVE-2013-1177

Published: 18/04/2013 Updated: 19/04/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager prior to 4.8.3.1 and 4.9.x prior to 4.9.2 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco network admission control manager and server system software 4.8.1

cisco network admission control manager and server system software 4.9.1

cisco network admission control manager and server system software 4.9.0

cisco network admission control manager and server system software

cisco network admission control manager and server system software 4.8.2

cisco network admission control manager and server system software 4.8.0

Vendor Advisories

Cisco Network Admission Control (NAC) Manager contains a vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code and take full control of the vulnerable system A successful attack could allow an unauthenticated attacker to access, create or modify any information in the NAC Manager database Cisco has released ...