Vulnerabilities > Cisco > Wide Area Application Services > 5.1.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2021-1438 Exposure of Resource to Wrong Sphere vulnerability in Cisco Wide Area Application Services
A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device.
local
low complexity
cisco CWE-668
5.5
2016-01-27 CVE-2015-6421 Resource Management Errors vulnerability in Cisco Wide Area Application Services
cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device reload) via crafted network traffic, aka Bug ID CSCus85330.
network
low complexity
cisco CWE-399
7.8
2014-05-29 CVE-2014-3285 Improper Input Validation vulnerability in Cisco Wide Area Application Services
Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (application-optimization handler reload) via a crafted SharePoint application, aka Bug ID CSCue47674.
network
low complexity
cisco CWE-20
5.0
2014-05-26 CVE-2014-2196 Code Injection vulnerability in Cisco Wide Area Application Services 5.1.1
Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479.
network
cisco CWE-94
critical
9.3
2013-08-01 CVE-2013-3444 OS Command Injection vulnerability in Cisco products
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
network
low complexity
cisco CWE-78
critical
9.0
2013-08-01 CVE-2013-3443 Improper Input Validation vulnerability in Cisco Wide Area Application Services
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.
network
low complexity
cisco CWE-20
critical
10.0