Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
References
Link | Resource |
---|---|
http://www.vupen.com/english/advisories/2010/2793 | Vendor Advisory |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b51501.shtml | Patch Vendor Advisory |
http://securitytracker.com/id?1024646 | |
http://secunia.com/advisories/42011 | Vendor Advisory |
http://www.securityfocus.com/bid/44468 | Patch |
http://osvdb.org/68927 |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-10-29 12:00
Updated : 2010-11-05 22:38
NVD link : CVE-2010-3036
Mitre link : CVE-2010-3036
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
cisco
- security_manager
- qos_policy_manager
- telepresence_readiness_assessment_manager
- ciscoworks_common_services
- unified_operations_manager
- unified_service_monitor
- ciscoworks_lan_management_solution