PT-2013-4341 · Cisco · Cisco Web Security Appliance
Publicado
2013-06-27
·
Atualizado
2013-06-28
·
CVE-2013-3383
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Web Security Appliance devices versions prior to 7.1.3-013
Cisco Web Security Appliance devices versions 7.5 prior to 7.5.0-838
Cisco Web Security Appliance devices versions 7.7 prior to 7.7.0-550
Description
The issue allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv4.
Recommendations
For versions prior to 7.1.3-013, update to version 7.1.3-013 or later.
For versions 7.5 prior to 7.5.0-838, update to version 7.5.0-838 or later.
For versions 7.7 prior to 7.7.0-550, update to version 7.7.0-550 or later.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Web Security Appliance