Vulnerabilities > CVE-2011-2738 - Remote Code Execution vulnerability in Multiple Cisco Products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
cisco
emc
critical
nessus

Summary

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

Nessus

NASL familyCGI abuses
NASL idCISCO_UOM_8_6.NASL
descriptionAccording to its self-reported version number, the version of Cisco Unified Operations Manager on the remote host has multiple vulnerabilities : - Multiple reflected XSS. (CVE-2011-0959, CVE-2011-0961, CVE-2011-0962) - Multiple blind SQL injections. (CVE-2011-0960) - A directory traversal in auditLog.do. (CVE-2011-0966) - An unspecified code execution vulnerability. (CVE-2011-2738)
last seen2020-06-01
modified2020-06-02
plugin id56485
published2011-10-13
reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/56485
titleCisco Unified Operations Manager < 8.6 Multiple Vulnerabilities