CiscoWorks Common Services Remote Command Injection Vulnerability
BID:50284
Info
CiscoWorks Common Services Remote Command Injection Vulnerability
| Bugtraq ID: | 50284 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3310 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2011 12:00AM |
| Updated: | Oct 19 2011 12:00AM |
| Credit: | Noam Rathaus from Beyond Security |
| Vulnerable: |
Cisco Lan Management Solution 4.0.1 Cisco Lan Management Solution 4.0 Cisco Lan Management Solution 3.2.1 Cisco Lan Management Solution 3.2 Cisco CiscoWorks Voice Manager 3.2 Cisco CiscoWorks Voice Manager 3.1 Cisco CiscoWorks Voice Manager 3.0 Cisco CiscoWorks QoS Policy Manager 4.1.6 Cisco CiscoWorks QoS Policy Manager 4.1.5 Cisco CiscoWorks QoS Policy Manager 4.1.4 Cisco CiscoWorks QoS Policy Manager 4.1.3 Cisco CiscoWorks QoS Policy Manager 4.1.2 Cisco CiscoWorks QoS Policy Manager 4.1.1 Cisco Cisco Unified Service Monitor 8.5 Cisco Cisco Unified Service Monitor 8.0 Cisco Cisco Unified Service Monitor 2.3 Cisco Cisco Unified Service Monitor 2.2 Cisco Cisco Unified Operations Manager (CUOM) 8.5 Cisco Cisco Unified Operations Manager (CUOM) 8.0 Cisco Cisco Unified Operations Manager (CUOM) 2.3 Cisco Cisco Unified Operations Manager (CUOM) 2.2 Cisco Cisco Security Manager (CSM) 4.0.1 SP1 Cisco Cisco Security Manager (CSM) 4.0.1 Cisco Cisco Security Manager (CSM) 3.3.1 SP3 Cisco Cisco Security Manager (CSM) 3.3.1 SP2 Cisco Cisco Security Manager (CSM) 3.3.1 SP1 Cisco Cisco Security Manager (CSM) 3.3.1 Cisco Cisco Security Manager (CSM) 3.2.2 SP4 Cisco Cisco Security Manager (CSM) 3.2.2 SP3 Cisco Cisco Security Manager (CSM) 3.2.2 SP2 Cisco Cisco Security Manager (CSM) 3.2.2 SP1 Cisco Cisco Security Manager (CSM) 3.2.2 Cisco Cisco Security Manager (CSM) 3.2.1 Cisco Cisco Security Manager (CSM) 4.1 Cisco Cisco Security Manager (CSM) 4.0 SP1 Cisco Cisco Security Manager (CSM) 4.0 Cisco Cisco Security Manager (CSM) 3.3 SP2 Cisco Cisco Security Manager (CSM) 3.3 SP1 Cisco Cisco Security Manager (CSM) 3.3 Cisco Cisco Security Manager (CSM) 3.2 SP1 Cisco Cisco Security Manager (CSM) 3.2 |
| Not Vulnerable: |
Cisco Cisco Security Manager (CSM) 4.0.1 SP2 Cisco Cisco Security Manager (CSM) 3.3.1 SP4 Cisco Cisco Security Manager (CSM) 4.1 SP1 |
Discussion
CiscoWorks Common Services Remote Command Injection Vulnerability
CiscoWorks Common Services is prone to a remote command-injection vulnerability.
A remote attacker can exploit this issue to execute arbitrary commands with system-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.
The following applications are affected:
CiscoWorks LAN Management Solution
Security Manager
Unified Operations Manager
Unified Service Monitor
CiscoWorks QoS Policy Manager
CiscoWorks Voice Manager
CiscoWorks Common Services is prone to a remote command-injection vulnerability.
A remote attacker can exploit this issue to execute arbitrary commands with system-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.
The following applications are affected:
CiscoWorks LAN Management Solution
Security Manager
Unified Operations Manager
Unified Service Monitor
CiscoWorks QoS Policy Manager
CiscoWorks Voice Manager
Exploit / POC
CiscoWorks Common Services Remote Command Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
CiscoWorks Common Services Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
CiscoWorks Common Services Remote Command Injection Vulnerability
References:
References: