CVE-2011-2547

Cisco SA 500 Series < 2.1.19 - Authenticated Remote Code Execution via Web Form Parameter Injection

Title source: llm
STIX 2.1

Description

The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45355
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68738
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025810
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48810

Scores

EPSS 0.0220
EPSS Percentile 80.6%

Details

CWE
CWE-264
Status published
Products (11)
cisco/sa500_software 1.0.14
cisco/sa500_software 1.0.15
cisco/sa500_software 1.0.17
cisco/sa500_software 1.0.39
cisco/sa500_software 1.1.21
cisco/sa500_software 1.1.42
cisco/sa500_software 1.1.65
cisco/sa500_software < 2.1.18
cisco/sa520
cisco/sa520w
... and 1 more
Published Jul 28, 2011
Tracked Since Feb 18, 2026