CiscoWorks Common Services Remote Code Execution Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
30 May 2008
5499
Views
RISK: Medium Risk
A vulnerability has been identified in CiscoWorks Common Services, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an unspecified error when processing user-supplied data, which could allow a remote attacker to execute arbitrary code on the user client machine.
Impact
- Remote Code Execution
System / Technologies affected
- CiscoWorks Common Services version 3.0.3
- CiscoWorks Common Services version 3.0.4
- CiscoWorks Common Services version 3.0.5
- CiscoWorks Common Services version 3.0.6
- CiscoWorks Common Services version 3.1
- CiscoWorks Common Services version 3.1.1
- Cisco Unified Operations Manager (CUOM) version 1.1
- Cisco Unified Operations Manager (CUOM) version 2.0
- Cisco Unified Operations Manager (CUOM) version 2.0.1
- Cisco Unified Operations Manager (CUOM) version 2.0.2
- Cisco Unified Operations Manager (CUOM) version 2.0.3
- Cisco Unified Service Monitor (CUSM) version 1.1
- Cisco Unified Service Monitor (CUSM) version 2.0
- Cisco Unified Service Monitor (CUSM) version 2.0.1
- CiscoWorks QoS Policy Manager (QPM) version 4.0
- CiscoWorks QoS Policy Manager (QPM) version 4.0.1
- CiscoWorks QoS Policy Manager (QPM) version 4.0.2
- CiscoWorks LAN Management Solution (LMS) version 2.5
- CiscoWorks LAN Management Solution (LMS) version 2.5.1
- CiscoWorks LAN Management Solution (LMS) version 2.6
- CiscoWorks LAN Management Solution (LMS) version 2.6 Update
- CiscoWorks LAN Management Solution (LMS) version 3.0
- CiscoWorks LAN Management Solution (LMS) version 3.0 December 2007 Update
- Cisco Security Manager (CSM) version 3.0
- Cisco Security Manager (CSM) version 3.0.1
- Cisco Security Manager (CSM) version 3.0.2
- Cisco Security Manager (CSM) version 3.1
- Cisco Security Manager (CSM) version 3.1.1
- Cisco Security Manager (CSM) version 3.2
- Cisco TelePresence Readiness Assessment Manager (CTRAM) version 1.0
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to CiscoWorks Common Services version 3.2 or apply patches :
http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-cd-one - cwcs3.x-sol-CSCsm77245-0.tar.gz (Solaris versions)
- cwcs3.x-win-CSCsm77245-0.zip (Windows versions)
Vulnerability Identifier
Source
Related Link
Share with