CVE-2011-2547
Cisco SA 500 Series < 2.1.19 - Authenticated Remote Code Execution via Web Form Parameter Injection
Title source: llmDescription
The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681.
References (5)
Core 5
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45355
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68738
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1025810
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48810
Scores
EPSS
0.0220
EPSS Percentile
80.6%
Details
CWE
CWE-264
Status
published
Products (11)
cisco/sa500_software
1.0.14
cisco/sa500_software
1.0.15
cisco/sa500_software
1.0.17
cisco/sa500_software
1.0.39
cisco/sa500_software
1.1.21
cisco/sa500_software
1.1.42
cisco/sa500_software
1.1.65
cisco/sa500_software
< 2.1.18
cisco/sa520
cisco/sa520w
... and 1 more
Published
Jul 28, 2011
Tracked Since
Feb 18, 2026