cbcvebase.
CVE-2008-3820
published 2009-01-22

CVE-2008-3820: Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which…

PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.38%
68.9th percentile
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscosecurity_manager
ciscosecurity_manager
ciscosecurity_manager
ciscosecurity_manager
ciscosecurity_manager

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.