CVE-2013-3443
published 2013-08-01CVE-2013-3443: The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.00%
92.5th percentile
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | waas_central_manager | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WAAS Central Manager Remote Code Execution Vulnerability
vendor_cisco·2013-07-31·CVSS 10.0
CVE-2013-3443 [CRITICAL] CWE-20 Cisco WAAS Central Manager Remote Code Execution Vulnerability
Cisco WAAS Central Manager Remote Code Execution Vulnerability
Cisco Wide Area Application Services (WAAS) when configured as Central Manager (CM), contains a vulnerability that could allow an unauthenticated, remote attacker to execute
arbitrary code on the affected system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-waascm
Cisco
Cisco WAAS Central Manager Remote Code Execution Vulnerability
vendor_cisco
CVE-2013-3443 Cisco WAAS Central Manager Remote Code Execution Vulnerability
CVE-2013-3443: Cisco WAAS Central Manager Remote Code Execution Vulnerability
Cisco Wide Area Application Services (WAAS) when configured as Central Manager (CM), contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the affected system. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuh26626, CSCuh26626
GHSA
GHSA-6h72-hh8m-p9h2: The web service framework in Cisco WAAS Software 4
ghsa_unreviewed·2022-05-17
CVE-2013-3443 [HIGH] CWE-20 GHSA-6h72-hh8m-p9h2: The web service framework in Cisco WAAS Software 4
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/95877http://secunia.com/advisories/54367http://secunia.com/advisories/54372http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-waascmhttp://www.securityfocus.com/bid/61542http://www.securitytracker.com/id/1028851https://exchange.xforce.ibmcloud.com/vulnerabilities/86121http://osvdb.org/95877http://secunia.com/advisories/54367http://secunia.com/advisories/54372http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-waascmhttp://www.securityfocus.com/bid/61542http://www.securitytracker.com/id/1028851https://exchange.xforce.ibmcloud.com/vulnerabilities/86121
2013-08-01
Published