← Back

CVE-2013-3383

nvd nist
Published: Jun 27, 2013Modified: Apr 29, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv4, aka Bug ID CSCzv69294.

Affected (3)

1 product
Ironport Asyncos
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 7.1.3
Version 7.5
Version 7.7
Running on/withPlatform Versions
Cisco
Web Security Appliance
All versions

Timeline

No history available yet.