Remote Command Execution in CiscoWorks Internetwork Performance Monitor by Cisco
CVE-2008-1157
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 14 March 2008
Summary
The vulnerability in CiscoWorks Internetwork Performance Monitor (IPM) 2.6 allows attackers to execute arbitrary commands on the affected system. This is achieved through the creation of a process that can open a command shell, which subsequently listens on a randomly chosen TCP port. As a result, unauthorized users may gain control over the device, significantly compromising network security and integrity. It is crucial for users of Cisco IPM to apply recommended patches and employ security measures to mitigate the risks associated with this vulnerability.
References
EPSS Score
9% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved