- Description
- The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.
- Source
- ykramarz@cisco.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-94
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:security_agent:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6DD0915-7671-42CD-8DF3-0B685389C528"
},
{
"criteria": "cpe:2.3:a:cisco:security_agent:5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "734B38F1-6FEC-4A94-B1C9-D076750A133F"
},
{
"criteria": "cpe:2.3:a:cisco:security_agent:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8805C68E-E152-4089-B74C-1B7703ECC064"
}
],
"operator": "OR"
}
]
}
]