CVE Feed

    Dashboard / CVE / CVE-2013-3444

    CVE-2013-3444

    The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.

    Published:Jul 31, 2013
    Last Modified:Apr 11, 2025
    EPS:Jul 31, 2013
    EPSS Score:0.02636
    CVSS Score:9

    Affected Products

    Vendor
    Cisco
    Product
    Application And Content Networking System Software
    Vendor
    Cisco
    Product
    Enterprise Content Delivery Network Software
    Vendor
    Cisco
    Product
    Internet Streamer Content Delivery System
    Vendor
    Cisco
    Product
    Videoscape Delivery System For Internet Streamer
    Vendor
    Cisco
    Product
    Videoscape Delivery System Origin Server
    Vendor
    Cisco
    Product
    Videoscape Distribution Suite Optimization Engine
    Vendor
    Cisco
    Product
    Videoscape Distribution Suite Service Broker
    Vendor
    Cisco
    Product
    Wide Area Application Services

    Exploits

    No exploit reference

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High