PT-2008-2751 · Cisco · Ciscoworks Internetwork Performance Monitor

Published

2008-03-14

·

Updated

2017-08-08

·

CVE-2008-1157

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco CiscoWorks Internetwork Performance Monitor (IPM) version 2.6
Description The issue allows remote attackers to execute arbitrary commands due to a process created by Cisco CiscoWorks Internetwork Performance Monitor (IPM) that executes a command shell and listens on a randomly chosen TCP port.
Recommendations For Cisco CiscoWorks Internetwork Performance Monitor (IPM) version 2.6, consider disabling the process that executes the command shell until a patch is available. Restrict access to the TCP port used by the process to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1157

Affected Products

Ciscoworks Internetwork Performance Monitor