Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CiscoWorks Common Services Arbitrary Command Execution Vulnerability

cisco-sa-20111019-cs · Critical · Published · Updated

CiscoWorks Common Services for Microsoft Windows contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands on the affected system with the privileges of a system administrator. Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs. Note:��Effective October 18, 2011, Cisco moved the current list of Cisco Security Advisories and Responses published by Cisco PSIRT. The new location is https://sec.cloudapps.cisco.com/security/center/publicationListing. You can also navigate to this page from the Cisco Products and Services menu of the Cisco Security (SIO) Portal. Following this transition, new Cisco Security Advisories and Responses will be published to the new location. Although the URL has changed, the content of security documents and the vulnerability policy are not impacted. Cisco will continue to disclose security vulnerabilities in accordance with the published Security Vulnerability Policy.

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds for this vulnerability.

CVEsCVE-2011-3310
Cisco Bug IDsCSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, CSCtt25535
CVSS ScoreBase 9.0
Base 9.0 AV:N/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
CiscoWorks Common Services (CS), CiscoWorks LAN Management Solution (LMS), CiscoWorks QoS Policy Manager (QPM), Cisco Unified Operations Manager, Cisco Unified Service Monitor, Cisco Security Manager, CiscoWorks Voice Manager

Related Products

Product CVE Evidence
CiscoWorks Voice Manager CVE-2011-3310 Cisco OpenVuln
CiscoWorks QoS Policy Manager (QPM) CVE-2011-3310 Cisco OpenVuln
CiscoWorks LAN Management Solution (LMS) CVE-2011-3310 Cisco OpenVuln
CiscoWorks Common Services (CS) CVE-2011-3310 Cisco OpenVuln
Cisco Unified Service Monitor CVE-2011-3310 Cisco OpenVuln
Cisco Unified Operations Manager CVE-2011-3310 Cisco OpenVuln
Cisco Security Manager CVE-2011-3310 Cisco OpenVuln