CVE-2008-3820

Cisco Security Manager 3.1-3.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33381
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48134
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021619
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0214
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33633
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6192a.shtml

Scores

EPSS 0.0138
EPSS Percentile 69.3%

Details

Status published
Products (5)
cisco/security_manager
cisco/security_manager 3.1
cisco/security_manager 3.1.1 (2 CPE variants)
cisco/security_manager 3.2 (2 CPE variants)
cisco/security_manager 3.2.1 (2 CPE variants)
Published Jan 22, 2009
Tracked Since Feb 18, 2026