HIGH · 10.0

CVE-2010-3036

Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on ...

Vulnerability Description

Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoCiscoworks Common Services3.0.5
CiscoCiscoworks Lan Management Solution2.6
CiscoQos Policy Manager4.0
CiscoSecurity Manager3.0.2
CiscoTelepresence Readiness Assessment Manager1.0
CiscoUnified Operations Manager2.0.1
CiscoUnified Service Monitor2.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3036?

CVE-2010-3036 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on ...

How severe is CVE-2010-3036?

CVE-2010-3036 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3036?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ciscoworks Common Services, Cisco Ciscoworks Lan Management Solution, Cisco Qos Policy Manager, Cisco Security Manager, Cisco Telepresence Readiness Assessment Manager.