Remote Command Execution in CiscoWorks Internetwork Performance Monitor by Cisco
CVE-2008-1157

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
14 March 2008

Summary

The vulnerability in CiscoWorks Internetwork Performance Monitor (IPM) 2.6 allows attackers to execute arbitrary commands on the affected system. This is achieved through the creation of a process that can open a command shell, which subsequently listens on a randomly chosen TCP port. As a result, unauthorized users may gain control over the device, significantly compromising network security and integrity. It is crucial for users of Cisco IPM to apply recommended patches and employ security measures to mitigate the risks associated with this vulnerability.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.