Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE)
Published Apr 21, 2006
7.5
HIGHCVSS 2.0
EPSS 2.71%
Description
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE). NOTE: other issues might be addressed by the Cisco advisory.
Affected products
No data.
Configuration 1
- n/a
- 2.0
- 2.0
- 2.1
- 2.1
- 2.2
- 2.2
- 2.3
- 2.3
- 2.4
- 2.4
- 2.5
- 2.5
- 2.6
- 2.6
- 2.7
- 2.7
- 2.8
- 2.8
- 2.9
- 2.9
- 2.10
- 2.10
- 2.11
- 2.11
- 2.12
- 2.12
- 2.13
- 2.13
Configuration 2
- n/a
- 1.7
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (14)
- http://secunia.com/advisories/19736 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19739 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19741 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1015965 vdb-entryx_refsource_SECTRACKPatch
- http://www.assurance.com.au/advisories/200604-cisco.txt x_refsource_MISC
- http://www.cisco.com/warp/public/707/cisco-sa-20060419-wlse.shtml vendor-advisoryx_refsource_CISCOPatch
- http://www.cisco.com/warp/public/707/cisco-sr-20060419-priv.shtml vendor-advisoryx_refsource_CISCOPatch
- http://www.osvdb.org/24813 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/431367/30/5490/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/431371/30/5490/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17609 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/1434 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/1435 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25884 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.