CVE-2013-3444
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 4.21% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- cisco/wide area application services · cisco/application and content networking system software · cisco/enterprise content delivery network software · cisco/internet streamer content delivery system · cisco/videoscape delivery system for internet streamer · cisco/videoscape delivery system origin server · cisco/videoscape distribution suite optimization engine · cisco/videoscape distribution suite service broker
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/54367
- http://secunia.com/advisories/54369
- http://secunia.com/advisories/54370
- http://secunia.com/advisories/54372
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cmVendor Advisory
- http://www.securityfocus.com/bid/61543
- http://www.securitytracker.com/id/1028852
- http://www.securitytracker.com/id/1028853
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86122
- http://secunia.com/advisories/54367
- http://secunia.com/advisories/54369
- http://secunia.com/advisories/54370
- http://secunia.com/advisories/54372
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130731-cmVendor Advisory
- http://www.securityfocus.com/bid/61543
- http://www.securitytracker.com/id/1028852
- http://www.securitytracker.com/id/1028853
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86122
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.