CVE-2013-3444 (CNNVD-201308-002)
中文标题:
多款思科产品Web框架操作系统命令注入漏洞
英文标题:
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and ...
漏洞描述
中文描述:
Cisco Wide Area Application Services(WAAS)是美国思科(Cisco)公司的一套广域网链路加速软件。该软件主要用于带宽小和延时大的链路环境。 多款思科产品在配置为中心管理模式中运行时,Web框架内存在安全漏洞。远程经过授权的攻击者可通过登录到受影响系统的GUI并追加任意代码值传递到系统,利用该漏洞在受影响系统上和受影响系统管理的设备上执行任意命令。以下版本受到影响:Cisco WAAS Software 4.x之前的版本和5.0.3e之前的5.x版本,5.1.1c之前的5.1.x版本,2.1之前的5.2.x版本;Cisco ACNS Software 4.x版本和5.5.29.2之前的5.x版本;Cisco ECDS Software 2.5.6之前的2.x版本;Cisco CDS-IS Software 2.6.3.b50之前的2.x版本,3.1.2b54之前的3.1.x版本;Cisco VDS-IS Software 3.2.1.b9之前的3.2.x版本;Cisco VDS-SB Software 1.1.0-b96之前的1.x版本;Cisco VDS-OE Software 1.0.1之前的1.x版本;Cisco VDS-OS Software 1.x版本。
英文描述:
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before 3.2.1.b9; Cisco VDS-SB Software 1.x before 1.1.0-b96; Cisco VDS-OE Software 1.x before 1.0.1; and Cisco VDS-OS Software 1.x in central-management mode allows remote authenticated users to execute arbitrary commands by appending crafted strings to values in GUI fields, aka Bug IDs CSCug40609, CSCug48855, CSCug48921, CSCug48872, CSCuh21103, CSCuh21020, and CSCug56790.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | wide_area_application_services | 4.1.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.1.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.1.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.1.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.1.5 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.1.5:a:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.1.7 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.1.7:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.3.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.3.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.3.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.3.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.3.5 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.3.5:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 5.0.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:5.0.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 5.0.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:5.0.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.2.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.2.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.2.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.2.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.4.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.4.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.4.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.4.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.4.5 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.4.5:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.4.7 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.4.7:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 5.1.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:5.1.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 5.2 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:5.2:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.1 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.1:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.3 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.3:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.5 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.5:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.7 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.7:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.9 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.9:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.11 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.11:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.13 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.13:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.17 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.17:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.19 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.19:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.21 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.21:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.23 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.23:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.25 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.25:*:*:*:*:*:*:*
|
| cisco | wide_area_application_services | 4.0.27 | - | - |
cpe:2.3:a:cisco:wide_area_application_services:4.0.27:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.1.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.1.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.7.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.7.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.9.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.9.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.11.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.11.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 4.2.13.1 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:4.2.13.1:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.1 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.1:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.3.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.3.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.5.9 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.5.9:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.7.10 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.7.10:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.9.9 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.9.9:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.11.6 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.11.6:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.13.2 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.13.2:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.15.1 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.15.1:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.0.17.6 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.0.17.6:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.1.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.1.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.3.15 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.3.15:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.5.2 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.5.2:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.7.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.7.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.9.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.9.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.11.6 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.11.6:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.13.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.13.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.1.15.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.1.15.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.4 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.4:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.4.1.10 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.4.1.10:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.4.3.17 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.4.3.17:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.4.5.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.4.5.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.4.7.3 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.4.7.3:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.1.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.1.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.3.1 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.3.1:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.5.4 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.5.4:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.7.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.7.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.9.9 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.9.9:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.11.2 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.11.2:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.13.7 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.13.7:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.15.2 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.15.2:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.17 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.17:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.19 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.19:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.21 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.21:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.23 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.23:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.25 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.25:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.27 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.27:*:*:*:*:*:*:*
|
| cisco | application_and_content_networking_system_software | 5.5.29 | - | - |
cpe:2.3:a:cisco:application_and_content_networking_system_software:5.5.29:*:*:*:*:*:*:*
|
| cisco | enterprise_content_delivery_network_software | 2.0 | - | - |
cpe:2.3:a:cisco:enterprise_content_delivery_network_software:2.0:*:*:*:*:*:*:*
|
| cisco | enterprise_content_delivery_network_software | 2.5.3 | - | - |
cpe:2.3:a:cisco:enterprise_content_delivery_network_software:2.5.3:*:*:*:*:*:*:*
|
| cisco | enterprise_content_delivery_network_software | 2.5.5 | - | - |
cpe:2.3:a:cisco:enterprise_content_delivery_network_software:2.5.5:*:*:*:*:*:*:*
|
| cisco | internet_streamer_content_delivery_system | 2.0 | - | - |
cpe:2.3:a:cisco:internet_streamer_content_delivery_system:2.0:*:*:*:*:*:*:*
|
| cisco | internet_streamer_content_delivery_system | 2.6 | - | - |
cpe:2.3:a:cisco:internet_streamer_content_delivery_system:2.6:*:*:*:*:*:*:*
|
| cisco | internet_streamer_content_delivery_system | 3.1 | - | - |
cpe:2.3:a:cisco:internet_streamer_content_delivery_system:3.1:*:*:*:*:*:*:*
|
| cisco | videoscape_delivery_system_for_internet_streamer | 1.0.0 | - | - |
cpe:2.3:a:cisco:videoscape_delivery_system_for_internet_streamer:1.0.0:*:*:*:*:*:*:*
|
| cisco | videoscape_delivery_system_for_internet_streamer | 3.2.0 | - | - |
cpe:2.3:a:cisco:videoscape_delivery_system_for_internet_streamer:3.2.0:*:*:*:*:*:*:*
|
| cisco | videoscape_delivery_system_for_internet_streamer | 3.2.1 | - | - |
cpe:2.3:a:cisco:videoscape_delivery_system_for_internet_streamer:3.2.1:*:*:*:*:*:*:*
|
| cisco | videoscape_delivery_system_origin_server | 1.0 | - | - |
cpe:2.3:a:cisco:videoscape_delivery_system_origin_server:1.0:*:*:*:*:*:*:*
|
| cisco | videoscape_distribution_suite_optimization_engine | 1.0.0 | - | - |
cpe:2.3:a:cisco:videoscape_distribution_suite_optimization_engine:1.0.0:*:*:*:*:*:*:*
|
| cisco | videoscape_distribution_suite_service_broker | 1.0.0 | - | - |
cpe:2.3:a:cisco:videoscape_distribution_suite_service_broker:1.0.0:*:*:*:*:*:*:*
|
| cisco | videoscape_distribution_suite_service_broker | 1.0.1 | - | - |
cpe:2.3:a:cisco:videoscape_distribution_suite_service_broker:1.0.1:*:*:*:*:*:*:*
|
| cisco | videoscape_distribution_suite_service_broker | 1.1.0 | - | - |
cpe:2.3:a:cisco:videoscape_distribution_suite_service_broker:1.1.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:L/Au:S/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2013-3444 |
2025-11-11 15:18:36 | 2025-11-11 07:33:35 |
| NVD | nvd_CVE-2013-3444 |
2025-11-11 14:54:15 | 2025-11-11 07:42:22 |
| CNNVD | cnnvd_CNNVD-201308-002 |
2025-11-11 15:09:23 | 2025-11-11 07:50:51 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201308-002
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:S/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 90
- data_sources: ['cve'] -> ['cve', 'nvd']