Description
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/33381
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48134
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1021619
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0214
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33633
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6192a.shtml
Scores
EPSS
0.0138
EPSS Percentile
69.3%
Details
Status
published
Products (5)
cisco/security_manager
cisco/security_manager
3.1
cisco/security_manager
3.1.1 (2 CPE variants)
cisco/security_manager
3.2 (2 CPE variants)
cisco/security_manager
3.2.1 (2 CPE variants)
Published
Jan 22, 2009
Tracked Since
Feb 18, 2026