CVE-2009-0622

Cisco Application Control Engine Module < A2(1.2) and ACE 4710 < A1(8a) - Authenticated OS Command Injection via CLI

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8a) allows remote authenticated users to execute arbitrary operating-system commands through a command line interface (CLI).

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33900

Scores

EPSS 0.0147
EPSS Percentile 71.1%

Details

Status published
Products (3)
cisco/ace_4710
cisco/application_control_engine_module 1.0
cisco/application_control_engine_module < 1.1
Published Feb 26, 2009
Tracked Since Feb 18, 2026