Remote Code Execution Vulnerability in Cisco WAAS Software
CVE-2013-3443

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 August 2013

Summary

The web service framework in Cisco WAAS Software versions prior to 5.0.3e, 5.1.1c, and 5.2.1 is susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploitation can occur through maliciously crafted POST requests sent to systems operating in a Central Manager configuration, posing serious security risks to affected installations.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.