CVE-2013-1192
The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote attackers to execute arbitrary commands on Windows client machines via a crafted element-manager.jnlp…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote attackers to execute arbitrary commands on Windows client machines via a crafted element-manager.jnlp file, aka Bug IDs CSCty17417 and CSCty10802.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/adaptive security appliance device manager · cisco/nexus 5000 · cisco/nexus 5010 · cisco/nexus 5010p switch · cisco/nexus 5020 · cisco/nexus 5020p switch · cisco/nexus 5548p · cisco/nexus 5548up · cisco/nexus 5596up · cisco/mds 9000
- Source
- psirt@cisco.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.