Cisco Security Monitoring Analysis And Response System vulnerabilities
2 known vulnerabilities affecting cisco/security_monitoring_analysis_and_response_system.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2007-0397MEDIUMCVSS 6.4v4.2.32007-01-20
CVE-2007-0397 [MEDIUM] CVE-2007-0397: The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Secu
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.
nvd
CVE-2006-3733HIGHCVSS 7.5PoCv4.2.02006-07-21
CVE-2006-3733 [HIGH] CWE-264 CVE-2006-3733: jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisc
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.
nvd