CVE-2003-0732
Summary
| CVE | CVE-2003-0732 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-10-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ciscoworks Cd1 | 1st | All | All | All |
| Operating System | Cisco | Ciscoworks Cd1 | 2nd | All | All | All |
| Operating System | Cisco | Ciscoworks Cd1 | 3rd | All | All | All |
| Operating System | Cisco | Ciscoworks Cd1 | 4th | All | All | All |
| Operating System | Cisco | Ciscoworks Cd1 | 5th | All | All | All |
| Application | Cisco | Ciscoworks Common Management Foundation | 2.0 | All | All | All |
| Application | Cisco | Ciscoworks Common Management Foundation | 2.1 | All | All | All |
| Application | Cisco | Resource Manager | 1.0 | All | All | All |
| Application | Cisco | Resource Manager | 1.1 | All | All | All |
| Application | Cisco | Resource Manager Essentials | 2.0 | All | All | All |
| Application | Cisco | Resource Manager Essentials | 2.1 | All | All | All |
| Application | Cisco | Resource Manager Essentials | 2.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.