CVE-2011-2738
Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 10.96% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- cisco/unified service monitor · cisco/ciscoworks lan management solution · cisco/unified operations manager · emc/ionix acm · emc/ionix asam · emc/ionix ip
- Source
- security_alert@emc.com
References
- http://secunia.com/advisories/45979Vendor Advisory
- http://secunia.com/advisories/46016Vendor Advisory
- http://secunia.com/advisories/46052Vendor Advisory
- http://secunia.com/advisories/46053Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtmlVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtmlVendor Advisory
- http://www.osvdb.org/75442
- http://www.securityfocus.com/archive/1/519646/100/0/threaded
- http://www.securityfocus.com/bid/49627
- http://www.securityfocus.com/bid/49644
- http://www.securitytracker.com/id?1026046
- http://www.securitytracker.com/id?1026047
- http://www.securitytracker.com/id?1026048
- http://www.securitytracker.com/id?1026059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69828
- http://secunia.com/advisories/45979Vendor Advisory
- http://secunia.com/advisories/46016Vendor Advisory
- http://secunia.com/advisories/46052Vendor Advisory
- http://secunia.com/advisories/46053Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtmlVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtmlVendor Advisory
- http://www.osvdb.org/75442
- http://www.securityfocus.com/archive/1/519646/100/0/threaded
- http://www.securityfocus.com/bid/49627
- http://www.securityfocus.com/bid/49644
- http://www.securitytracker.com/id?1026046
- http://www.securitytracker.com/id?1026047
- http://www.securitytracker.com/id?1026048
- http://www.securitytracker.com/id?1026059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69828
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.