First published: Fri Feb 18 2011(Updated: )
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Security Agent | =5.1 | |
Cisco Security Agent | =5.2 | |
Cisco Security Agent | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0364 is considered a critical vulnerability due to its ability to allow remote code execution.
To fix CVE-2011-0364, upgrade Cisco Security Agent to version 6.0.2.145 or later.
CVE-2011-0364 affects Cisco Security Agent versions 5.1, 5.2, and 6.0 prior to 6.0.2.145.
CVE-2011-0364 allows remote attackers to create arbitrary files and execute arbitrary code on vulnerable systems.
There is no officially stated workaround for CVE-2011-0364; updating to the patched version is recommended.