9
CVSSv2

CVE-2013-3384

Published: 27/06/2013 Updated: 30/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices prior to 7.1.3-013, 7.5 prior to 7.5.0-838, and 7.7 prior to 7.7.0-550; Email Security Appliance devices prior to 7.1.5-104, 7.3 prior to 7.3.2-026, 7.5 prior to 7.5.2-203, and 7.6 prior to 7.6.3-019; and Content Security Management Appliance devices prior to 7.2.2-110, 7.7 prior to 7.7.0-213, and 7.8 and 7.9 prior to 7.9.1-102 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL, aka Bug IDs CSCzv85726, CSCzv44633, and CSCzv24579.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ironport asyncos

cisco ironport asyncos 7.2

cisco ironport asyncos 7.3

cisco ironport asyncos 7.5

cisco ironport asyncos 7.6

cisco ironport asyncos 7.7

cisco ironport asyncos 7.8

cisco ironport asyncos 7.9