Vulnerabilities > Cisco > Security Manager > 3.1

DATE CVE VULNERABILITY TITLE RISK
2009-05-21 CVE-2009-1161 Path Traversal vulnerability in Cisco products
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.
network
low complexity
cisco CWE-22
critical
10.0
2009-01-22 CVE-2008-3820 Remote Unauthorized TCP Port Access vulnerability in Cisco Security Manager IPS Event Viewer
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
network
cisco
6.8