Release date: 2011-10-20
Updated on: 2011-10-20
Affected Systems:
Cisco Security Manager 4.x
Cisco Security Manager 3.x
Cisco uniied Operations Manager (CUOM) 8.x
Cisco uniied Operations Manager (CUOM) 2.x
Cisco CiscoWorks Voice Manager 3.x
Cisco CiscoWorks QoS Policy Manager 4.x
Unaffected system:
Cisco Security Manager 4.1 SP1
Cisco Security Manager 4.0.1 SP2
Cisco Security Manager 3.3.1 SP4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50284
Cve id: CVE-2011-3310
CiscoWorks Common Services is a general management service set shared by CiscoWorks applications.
CiscoWorks Common Services has a remote command injection vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary commands with system-level permissions on lower-level operating systems.
This vulnerability is caused by incorrect input verification in the CiscoWorks Home Page component. The Cisco Bug IDs include CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.
Affected applications include:
CiscoWorks LAN Management Solution
Security Manager
Unified Operations Manager
Uniied Service Monitor
CiscoWorks QoS Policy Manager
CiscoWorks Voice Manager
<* Source: Noam Rathaus (noamr@beyondsecurity.com)
Link: http://seclists.org/fulldisclosure/2011/Oct/723
Http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20111019-cs) and patches for this:
Cisco-sa-20111019-cs: CiscoWorks Common Services Arbitrary Command Execution Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs