// For flags

CVE-2011-3310

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoWorks Voice Manager, allows remote authenticated users to execute arbitrary commands via a crafted URL, aka Bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.

El componente de página de inicio ("Home Page") de Cisco CiscoWorks Common Services en versiones anteriores a 4.1 en Windows, tal como se usa en CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager y CiscoWorks Voice Manager, permite a usuarios autenticados remotos ejecutar comandos arbitrarios a través de una URL modificada. También conocido como Bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090 y CSCtt25535.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-08-29 CVE Reserved
  • 2011-10-19 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
<= 4.0.1
Search vendor "Cisco" for product "Ciscoworks Common Services" and version " <= 4.0.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
2.2
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "2.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.0.5
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.0.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.0.6
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.0.6"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.1
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.1.1
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.1.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.2
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected
Cisco
Search vendor "Cisco"
Ciscoworks Common Services
Search vendor "Cisco" for product "Ciscoworks Common Services"
3.3
Search vendor "Cisco" for product "Ciscoworks Common Services" and version "3.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Affected