5
CVE-2011-2042
- EPSS 1.08%
- Veröffentlicht 22.10.2011 02:59:19
- Zuletzt bearbeitet 16.06.2026 23:30:37
- Erkennungen
The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the engine name and database port via an unspecified request to UDP port 2638, aka Bug ID CSCsk35018.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ciscoworks Common Services Version 3.0
Cisco ≫ Ciscoworks Common Services Version 3.0.3
Cisco ≫ Ciscoworks Common Services Version 3.0.4
Cisco ≫ Ciscoworks Common Services Version 3.0.5
Cisco ≫ Ciscoworks Common Services Version 3.0.6
Cisco ≫ Ciscoworks Common Services Version 3.1
Cisco ≫ Ciscoworks Common Services Version 3.1.1
Cisco ≫ Ciscoworks Common Services Version 3.2
Cisco ≫ Ciscoworks Common Services Version 3.3
Cisco ≫ Ciscoworks Common Services Version 4.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.606 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_common_services_software/3.3/release/notes/cs33rel.html