CVE-2011-2547

The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:cisco:sa500_software:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.0.17:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.0.39:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.1.21:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.1.42:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sa500_software:1.1.65:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:sa520:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sa520w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sa540:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-07-28 22:55

Updated : 2024-02-28 11:41


NVD link : CVE-2011-2547

Mitre link : CVE-2011-2547

CVE.ORG link : CVE-2011-2547


JSON object : View

Products Affected

cisco

  • sa520w
  • sa540
  • sa500_software
  • sa520
CWE
CWE-264

Permissions, Privileges, and Access Controls