CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
BID:29409
Info
CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
| Bugtraq ID: | 29409 |
| Class: | Unknown |
| CVE: |
CVE-2008-2054 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2008 12:00AM |
| Updated: | May 28 2008 12:00AM |
| Credit: | Dave Lewis from Liquidmatrix.org |
| Vulnerable: |
Cisco TelePresence Readiness Assessment Manager (CTRAM) 1.0 Cisco QoS Policy Manager 4.0.2 Cisco QoS Policy Manager 4.0.1 Cisco QoS Policy Manager 4.0 Cisco QoS Policy Manager Cisco Lan Management Solution 2.5.1 Cisco Lan Management Solution 3.0 Cisco Lan Management Solution 2.6 Cisco Lan Management Solution 2.5 Cisco Lan Management Solution Cisco CiscoWorks Common Services 3.1.1 Cisco CiscoWorks Common Services 3.0.6 Cisco CiscoWorks Common Services 3.0.5 Cisco CiscoWorks Common Services 3.0.4 Cisco CiscoWorks Common Services 3.0.3 Cisco CiscoWorks Common Services 3.1 Cisco Cisco Unified Service Manager (CUSM) 2.0.1 Cisco Cisco Unified Service Manager (CUSM) 2.0 Cisco Cisco Unified Service Manager (CUSM) 1.1 Cisco Cisco Unified Operations Manager (CUOM) 2.0.3 Cisco Cisco Unified Operations Manager (CUOM) 2.0.2 Cisco Cisco Unified Operations Manager (CUOM) 2.0.1 Cisco Cisco Unified Operations Manager (CUOM) 2.0 Cisco Cisco Unified Operations Manager (CUOM) 1.1 Cisco Cisco Security Manager (CSM) 3.1.1 Cisco Cisco Security Manager (CSM) 3.0.2 Cisco Cisco Security Manager (CSM) 3.0.1 Cisco Cisco Security Manager (CSM) 3.2 Cisco Cisco Security Manager (CSM) 3.1 Cisco Cisco Security Manager (CSM) 3.0 |
| Not Vulnerable: |
Cisco CiscoWorks Common Services 3.2 |
Discussion
CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
CiscoWorks Common Services is prone to an unspecified remote code-execution vulnerability.
This issue allows remote attackers to execute arbitrary machine code on affected devices. Failed exploit attempts will likely result in denial-of-service conditions.
The vulnerability is documented in Cisco Bug ID CSCsm77245.
No further technical details are currently available. We will update this BID as more information emerges.
CiscoWorks Common Services is prone to an unspecified remote code-execution vulnerability.
This issue allows remote attackers to execute arbitrary machine code on affected devices. Failed exploit attempts will likely result in denial-of-service conditions.
The vulnerability is documented in Cisco Bug ID CSCsm77245.
No further technical details are currently available. We will update this BID as more information emerges.
Exploit / POC
CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
CiscoWorks Common Services Unspecified Remote Code Execution Vulnerability
References:
References:
- Cisco Homepage (Cisco)
- CiscoWorks Server CD-One Patches (Cisco)
- Cisco Security Advisory: CiscoWorks Common Services Arbitrary Code Execution Vul (Cisco Systems Product Security Incident Response Team
)