Vulnslist

find the latest Cisco vulnerabilities

Cisco Security Agent Remote Code Execution Vulnerabilities

cisco-sa-20111026-csa · Critical · Published · Updated

Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to perform remote code execution on the affected device. These vulnerabilities are in a third-party library (Oracle Outside In) and are documented in CERT-CC Vulnerability Note VU#520721 at http://www.kb.cert.org/vuls/id/520721 Cisco has released software updates that address these vulnerabilities. No workaround is available to mitigate these vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa. Note: Effective October 18, 2011, Cisco moved the current list of Cisco Security Advisories and Responses published by Cisco PSIRT. The new location is https://sec.cloudapps.cisco.com/security/center/publicationListing. You can also navigate to this page from the Cisco Products and Services menu of the Cisco Security (SIO) Portal. Following this transition, new Cisco Security Advisories and Responses will be published to the new location. Although the URL has changed, the content of security documents and the vulnerability policy are not impacted. Cisco will continue to disclose security vulnerabilities in accordance with the published Security Vulnerability Policy

Workarounds

No workaround information imported yet.

CVEsCVE-2011-0794, CVE-2011-0808
Cisco Bug IDsCSCtq29413
CVSS ScoreBase 10.0
Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco Security Agent

Related Products

Product CVE Evidence
Cisco Security Agent CVE-2011-0794 Cisco OpenVuln
Cisco Security Agent CVE-2011-0808 Cisco OpenVuln