PT-2013-4342 · Cisco · Cisco Content Security Management Appliance+2

Published

2013-06-27

·

Updated

2018-10-30

·

CVE-2013-3384

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance versions prior to 7.1.3-013 Cisco Web Security Appliance versions prior to 7.5.0-838 Cisco Web Security Appliance versions prior to 7.7.0-550 Cisco Email Security Appliance versions prior to 7.1.5-104 Cisco Email Security Appliance versions prior to 7.3.2-026 Cisco Email Security Appliance versions prior to 7.5.2-203 Cisco Email Security Appliance versions prior to 7.6.3-019 Cisco Content Security Management Appliance versions prior to 7.2.2-110 Cisco Content Security Management Appliance versions prior to 7.7.0-213 Cisco Content Security Management Appliance versions prior to 7.9.1-102
Description The web framework in Cisco devices allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL.
Recommendations For Cisco Web Security Appliance versions prior to 7.1.3-013, update to version 7.1.3-013 or later. For Cisco Web Security Appliance versions prior to 7.5.0-838, update to version 7.5.0-838 or later. For Cisco Web Security Appliance versions prior to 7.7.0-550, update to version 7.7.0-550 or later. For Cisco Email Security Appliance versions prior to 7.1.5-104, update to version 7.1.5-104 or later. For Cisco Email Security Appliance versions prior to 7.3.2-026, update to version 7.3.2-026 or later. For Cisco Email Security Appliance versions prior to 7.5.2-203, update to version 7.5.2-203 or later. For Cisco Email Security Appliance versions prior to 7.6.3-019, update to version 7.6.3-019 or later. For Cisco Content Security Management Appliance versions prior to 7.2.2-110, update to version 7.2.2-110 or later. For Cisco Content Security Management Appliance versions prior to 7.7.0-213, update to version 7.7.0-213 or later. For Cisco Content Security Management Appliance versions prior to 7.9.1-102, update to version 7.9.1-102 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3384

Affected Products

Cisco Content Security Management Appliance
Cisco Email Security Appliance
Cisco Web Security Appliance