Cisco Security Agent vulnerabilities
13 known vulnerabilities affecting cisco/security_agent.
Total CVEs
13
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2011-0364CRITICALCVSS 10.0PoCv5.1v5.2+1 more2011-02-19
CVE-2011-0364 [CRITICAL] CWE-94 CVE-2011-0364: The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 all
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.
nvd
CVE-2010-0148HIGHCVSS 7.8v5.22010-02-23
CVE-2010-0148 [HIGH] CVE-2010-0148: Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allow
Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allows remote attackers to cause a denial of service (kernel panic) via "a series of TCP packets."
nvd
CVE-2010-0147MEDIUMCVSS 6.5v5.1v5.2+1 more2010-02-23
CVE-2010-0147 [MEDIUM] CWE-89 CVE-2010-0147: SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117,
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2010-0146MEDIUMCVSS 6.8v6.02010-02-23
CVE-2010-0146 [MEDIUM] CWE-22 CVE-2010-0146: Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remo
Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
nvd
CVE-2007-5580CRITICALCVSS 10.0v2.1v3+16 more2007-12-15
CVE-2007-5580 [CRITICAL] CWE-119 CVE-2007-5580: Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0
Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.
nvd
CVE-2007-1068HIGHCVSS 7.2v5.0v5.12007-02-22
CVE-2007-1068 [HIGH] CWE-255 CVE-2007-1068: The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8)
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS Se
nvd
CVE-2007-1067HIGHCVSS 7.2v5.0v5.12007-02-22
CVE-2007-1067 [HIGH] CVE-2007-1067: Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.
nvd
CVE-2007-1066MEDIUMCVSS 6.8v5.0v5.12007-02-22
CVE-2007-1066 [MEDIUM] CVE-2007-1066: Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting "a
nvd
CVE-2007-1065MEDIUMCVSS 6.8v5.0v5.12007-02-22
CVE-2007-1065 [MEDIUM] CVE-2007-1065: Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.
nvd
CVE-2007-1064MEDIUMCVSS 6.8v5.0v5.12007-02-22
CVE-2007-1064 [MEDIUM] CVE-2007-1064: Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.
nvd
CVE-2006-5553HIGHCVSS 7.8v4.5v4.5.1+2 more2006-10-26
CVE-2006-5553 [HIGH] CVE-2006-5553: Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unifi
Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certain options.
nvd
CVE-2005-2280MEDIUMCVSS 5.0v4.52005-07-18
CVE-2005-2280 [MEDIUM] CVE-2005-2280: Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) v
Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet.
nvd
CVE-2004-1112MEDIUMCVSS 5.1v3v4.0+3 more2005-01-10
CVE-2004-1112 [MEDIUM] CVE-2004-1112: The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes
The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
nvd