// For flags

CVE-2003-0731

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-09-03 CVE Reserved
  • 2003-09-04 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Resource Manager
Search vendor "Cisco" for product "Resource Manager"
1.0
Search vendor "Cisco" for product "Resource Manager" and version "1.0"
-
Affected
Cisco
Search vendor "Cisco"
Resource Manager
Search vendor "Cisco" for product "Resource Manager"
1.1
Search vendor "Cisco" for product "Resource Manager" and version "1.1"
-
Affected
Cisco
Search vendor "Cisco"
Resource Manager Essentials
Search vendor "Cisco" for product "Resource Manager Essentials"
2.0
Search vendor "Cisco" for product "Resource Manager Essentials" and version "2.0"
-
Affected
Cisco
Search vendor "Cisco"
Resource Manager Essentials
Search vendor "Cisco" for product "Resource Manager Essentials"
2.1
Search vendor "Cisco" for product "Resource Manager Essentials" and version "2.1"
-
Affected
Cisco
Search vendor "Cisco"
Resource Manager Essentials
Search vendor "Cisco" for product "Resource Manager Essentials"
2.2
Search vendor "Cisco" for product "Resource Manager Essentials" and version "2.2"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Management Foundation
Search vendor "Cisco" for product "Ciscoworks Common Management Foundation"
2.0
Search vendor "Cisco" for product "Ciscoworks Common Management Foundation" and version "2.0"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Management Foundation
Search vendor "Cisco" for product "Ciscoworks Common Management Foundation"
2.1
Search vendor "Cisco" for product "Ciscoworks Common Management Foundation" and version "2.1"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Cd1
Search vendor "Cisco" for product "Ciscoworks Cd1"
1st
Search vendor "Cisco" for product "Ciscoworks Cd1" and version "1st"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Cd1
Search vendor "Cisco" for product "Ciscoworks Cd1"
2nd
Search vendor "Cisco" for product "Ciscoworks Cd1" and version "2nd"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Cd1
Search vendor "Cisco" for product "Ciscoworks Cd1"
3rd
Search vendor "Cisco" for product "Ciscoworks Cd1" and version "3rd"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Cd1
Search vendor "Cisco" for product "Ciscoworks Cd1"
4th
Search vendor "Cisco" for product "Ciscoworks Cd1" and version "4th"
-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Cd1
Search vendor "Cisco" for product "Ciscoworks Cd1"
5th
Search vendor "Cisco" for product "Ciscoworks Cd1" and version "5th"
-
Affected