CVE-2013-5488
Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote…
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to cause a denial of service (memory consumption) via simultaneous TCP sessions, aka Bug IDs CSCuh54766, CSCuh01267, CSCuh95976, and CSCuh95969.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/prime lan management solution · cisco/security manager · cisco/unified operations manager · cisco/unified service monitor
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5488Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30749
- http://www.securityfocus.com/bid/62333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87026
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5488Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30749
- http://www.securityfocus.com/bid/62333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87026
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.