VulnerabilityModified
CVE-2008-3820
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to…
MEDIUM 6.8EPSS 1.38%
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- cisco/security manager
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/33633Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6192a.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/33381
- http://www.securitytracker.com/id?1021619
- http://www.vupen.com/english/advisories/2009/0214
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48134
- http://secunia.com/advisories/33633Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6192a.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/33381
- http://www.securitytracker.com/id?1021619
- http://www.vupen.com/english/advisories/2009/0214
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48134
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.