| PROBLEM: | CiscoWorks Common Services contains a vulnerability that could allow a remote attacker to execute arbitrary code. |
| PLATFORM: | Cisco Unified Operations Manager (CUOM) 1.1 3.0.3 Cisco Unified Operations Manager (CUOM) 2.0 3.0.3 Cisco Unified Operations Manager (CUOM) 2.0.1 3.0.5 Cisco Unified Operations Manager (CUOM) 2.0.2 3.0.5 Cisco Unified Operations Manager (CUOM) 2.0.3 3.0.5 Cisco Unified Service Monitor (CUSM) 1.1 3.0.3 Cisco Unified Service Monitor (CUSM) 2.0 3.0.4 Cisco Unified Service Monitor (CUSM) 2.0.1 3.0.5 CiscoWorks QoS Policy Manager (QPM) 4.0, 4.0.1, and 4.0.2 3.0.5 CiscoWorks LAN Management Solution (LMS) 2.5, 2.5.1, 2.6 3.0.3 CiscoWorks LAN Management Solution (LMS) 2.6 Update 3.0.5 CiscoWorks LAN Management Solution (LMS) 3.0 3.1 CiscoWorks LAN Management Solution (LMS) 3.0 December 2007 Update 3.1.1 Cisco Security Manager (CSM) 3.0 3.0.3 Cisco Security Manager (CSM) 3.0.1 3.0.4 Cisco Security Manager (CSM) 3.0.2 3.0.5 Cisco Security Manager (CSM) 3.1 and 3.1.1 3.0.5 Cisco Security Manager (CSM) 3.2 3.1 Cisco TelePresence Readiness Assessment Manager (CTRAM) 1.0 3.0.5 |
| DAMAGE: | Remote execute arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
9.3 7.7 (AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-300.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a00809a1f14.shtml |
| CVE: | CVE-2008-2054 |
[***** Start Cisco Security Advisory Document ID: 105452 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
CiscoWorks Common Services contains a vulnerability that could allow a remote attacker to execute arbitrary code.
Cisco has released free software updates that address this vulnerability.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080528-cw.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 105452 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org