CVE-2013-3443

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/08/2013
Last modified:
11/04/2025

Description

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:wide_area_application_services:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.11:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.13:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.17:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.19:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.21:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.23:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.0.27:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:4.1.1:a:*:*:*:*:*:*