PT-2008-2751 · Cisco · Ciscoworks Internetwork Performance Monitor

Publicado

2008-03-14

·

Atualizado

2017-08-08

·

CVE-2008-1157

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco CiscoWorks Internetwork Performance Monitor (IPM) version 2.6
Description The issue allows remote attackers to execute arbitrary commands due to a process created by Cisco CiscoWorks Internetwork Performance Monitor (IPM) that executes a command shell and listens on a randomly chosen TCP port.
Recommendations For Cisco CiscoWorks Internetwork Performance Monitor (IPM) version 2.6, consider disabling the process that executes the command shell until a patch is available. Restrict access to the TCP port used by the process to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1157

Produtos afetados

Ciscoworks Internetwork Performance Monitor