CVE-2010-3036: Buffer Overflow
Published Oct 29, 2010
·Updated
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
Affected Software
21 affected components
Cisco CiscoWorks Common Services=3.0.5
Cisco CiscoWorks Common Services=3.0.6
Cisco CiscoWorks Common Services=3.1
Cisco CiscoWorks Common Services=3.1.1
Cisco CiscoWorks Common Services=3.2
Cisco CiscoWorks Common Services=3.3
Cisco CiscoWorks LAN Management Solution=2.6-update
Cisco CiscoWorks LAN Management Solution=3.0
Cisco CiscoWorks LAN Management Solution=3.0-december_2007
Cisco CiscoWorks LAN Management Solution=3.1
Cisco CiscoWorks LAN Management Solution=3.2
Cisco Qos Policy Manager=4.0
Cisco Qos Policy Manager=4.0.1
Cisco Qos Policy Manager=4.0.2
Cisco Security Manager=3.0.2
Cisco Security Manager=3.2
Cisco TelePresence Readiness Assessment Manager=1.0
Cisco Unified Operations Manager=2.0.1
Cisco Unified Operations Manager=2.0.2
Cisco Unified Operations Manager=2.0.3
Cisco Unified Service Monitor=2.0.1
Remediation
Patch Available
Event History
Oct 29, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
07:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-3036?
CVE-2010-3036 is considered to have a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2010-3036?
To fix CVE-2010-3036, you should upgrade CiscoWorks Common Services to version 4.0 or later.
3
What systems are affected by CVE-2010-3036?
CVE-2010-3036 affects CiscoWorks Common Services versions 3.0.5, 3.0.6, 3.1, 3.1.1, 3.2, 3.3, and others.
4
Can CVE-2010-3036 be exploited remotely?
Yes, CVE-2010-3036 can be exploited remotely via TCP port 443 or 1741.
5
What type of vulnerability is CVE-2010-3036?
CVE-2010-3036 is a multiple buffer overflow vulnerability in the authentication functionality.