CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.
2003-10-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | resource_manager | 1.0 | Yes |
Application | cisco | resource_manager | 1.1 | Yes |
Application | cisco | resource_manager_essentials | 2.0 | Yes |
Application | cisco | resource_manager_essentials | 2.1 | Yes |
Application | cisco | resource_manager_essentials | 2.2 | Yes |
Application | cisco | ciscoworks_common_management_foundation | 2.0 | Yes |
Application | cisco | ciscoworks_common_management_foundation | 2.1 | Yes |
Operating System | cisco | ciscoworks_cd1 | 1st | Yes |
Operating System | cisco | ciscoworks_cd1 | 2nd | Yes |
Operating System | cisco | ciscoworks_cd1 | 3rd | Yes |
Operating System | cisco | ciscoworks_cd1 | 4th | Yes |
Operating System | cisco | ciscoworks_cd1 | 5th | Yes |