Vulnerabilities
Vulnerable Software
Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."
CVSS Score
9.0
EPSS Score
0.002
Published
2009-02-26
Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials during installation."
CVSS Score
10.0
EPSS Score
0.006
Published
2009-02-26
Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.
CVSS Score
10.0
EPSS Score
0.007
Published
2009-02-26
Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files.
CVSS Score
8.5
EPSS Score
0.006
Published
2009-02-26


Contact Us

Shodan ® - All rights reserved