HIGH · 10.0

CVE-2011-2738

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and mu...

Vulnerability Description

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoUnified Service Monitor<= 8.5
CiscoCiscoworks Lan Management Solution3.0
CiscoUnified Operations Manager<= 8.5
EmcIonix Acm<= 2.3
EmcIonix Asam<= 3.2.0.2
EmcIonix Ip<= 8.1.1.1

References

FAQ

What is CVE-2011-2738?

CVE-2011-2738 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and mu...

How severe is CVE-2011-2738?

CVE-2011-2738 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2738?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Service Monitor, Cisco Ciscoworks Lan Management Solution, Cisco Unified Operations Manager, Emc Ionix Acm, Emc Ionix Asam.