CVE-2013-3444
published 2013-08-01CVE-2013-3444: The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before…
PriorityP353critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
4.21%
89.8th percentile
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
| cisco | application_and_content_networking_system_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
vendor_cisco·2013-07-31·CVSS 9.0
CVE-2013-3444 [CRITICAL] CWE-20 Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
Multiple Cisco content network and video delivery products contain a vulnerability
when they are configured to run in central management mode. This vulnerability could allow an authenticated but unprivileged, remote attacker to
execute arbitrary code on the affected system and on the devices managed by the affected system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cm
Cisco
Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
vendor_cisco
CVE-2013-3444 Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
CVE-2013-3444: Authenticated Command Injection Vulnerability in Multiple Cisco Content Network and Video Delivery Products
Multiple Cisco content network and video delivery products contain a vulnerability when they are configured to run in central management mode. This vulnerability could allow an authenticated but unprivileged, remote attacker to execute arbitrary code on the affected system and on the devices managed by the affected system. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCug40609, CSCug48855, CSCug48872, CSCug40609, CSCug48855
GHSA
GHSA-gcm5-w3f4-h48v: The web framework in Cisco WAAS Software before 4
ghsa_unreviewed·2022-05-17
CVE-2013-3444 [HIGH] CWE-78 GHSA-gcm5-w3f4-h48v: The web framework in Cisco WAAS Software before 4
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/54367http://secunia.com/advisories/54369http://secunia.com/advisories/54370http://secunia.com/advisories/54372http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cmhttp://www.securityfocus.com/bid/61543http://www.securitytracker.com/id/1028852http://www.securitytracker.com/id/1028853https://exchange.xforce.ibmcloud.com/vulnerabilities/86122http://secunia.com/advisories/54367http://secunia.com/advisories/54369http://secunia.com/advisories/54370http://secunia.com/advisories/54372http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cmhttp://www.securityfocus.com/bid/61543http://www.securitytracker.com/id/1028852http://www.securitytracker.com/id/1028853https://exchange.xforce.ibmcloud.com/vulnerabilities/86122
2013-08-01
Published