Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
BID:61543
Info
Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
| Bugtraq ID: | 61543 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3444 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2013 12:00AM |
| Updated: | Jul 31 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Application & Content Networking Software 5.5.17 Cisco Application & Content Networking Software 5.5.11 Cisco Application & Content Networking Software 5.5.7 Cisco Application & Content Networking Software 5.2 Cisco Application & Content Networking Software 5.1.9 Cisco Application & Content Networking Software 5.1 Cisco Application & Content Networking Software 5.0.5 Cisco Application & Content Networking Software 5.0.3 Cisco Application & Content Networking Software 5.0.1 Cisco Application & Content Networking Software 5.0 Cisco Application & Content Networking Software 4.2.11 Cisco Application & Content Networking Software 4.2.9 Cisco Application & Content Networking Software 4.2 Cisco Application & Content Networking Software 4.1.3 Cisco Application & Content Networking Software 4.0.3 |
| Not Vulnerable: | |
Discussion
Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
Multiple Cisco Content Network and Video Delivery products are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an unprivileged attacker to execute arbitrary commands on the affected system and completely compromise the affected devices.
This issue is being tracked by Cisco bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
Multiple Cisco Content Network and Video Delivery products are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an unprivileged attacker to execute arbitrary commands on the affected system and completely compromise the affected devices.
This issue is being tracked by Cisco bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
Exploit / POC
Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Cisco Content Network and Video Delivery Products Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )