CVE-2013-1125
Last modified
CVE-2013-1125 is a vulnerability of currently unknown severity. The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services Manager does not properly validate input, which allows local users to obtain root privileges via unspecified vectors, aka Bug IDs CSCue46001, CSCud95790, CSCue46021, CSCue46025, CSCue46023, CSCue46058, CSCue46013, CSCue46031, CSCue46035, and CSCue46042.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services Manager does not properly validate input, which allows local users to obtain root privileges via unspecified vectors, aka Bug IDs CSCue46001, CSCud95790, CSCue46021, CSCue46025, CSCue46023, CSCue46058, CSCue46013, CSCue46031, CSCue46035, and CSCue46042.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Networking Manager | All versions |
| Cisco | Context Directory Agent | All versions |
| Cisco | Identity Services Engine Software | All versions |
| Cisco | Network Services Manager | All versions |
| Cisco | Prime Collaboration | All versions |
| Cisco | Prime Lan Management Solution | All versions |
| Cisco | Prime Network Control System | All versions |
| Cisco | Quad | All versions |
| Cisco | Secure Access Control System | All versions |
| Cisco | Unified Provisioning Manager | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1125?
How severe is CVE-2013-1125?
How do I fix CVE-2013-1125?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1119Buffer overflow in Cisco WebEx Recording Format (WRF) player…
- CVE-2013-1120Multiple cross-site request forgery (CSRF) vulnerabilities o…
- CVE-2013-1121The regex engine in the BGP implementation in Cisco NX-OS, w…
- CVE-2013-1122Cisco NX-OS on the Nexus 7000, when a certain Overlay Transp…
- CVE-2013-1123Multiple cross-site scripting (XSS) vulnerabilities in the s…
- CVE-2013-1124The Cisco Network Admission Control (NAC) agent on Mac OS X …
- CVE-2013-1128Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2013-1129Memory leak in Cisco Unity Connection 9.x allows remote atta…
- CVE-2013-1130Cisco AnyConnect Secure Mobility Client on Mac OS X uses wea…
- CVE-2013-1131Cisco Small Business Wireless Access Points WAP200, WAP2000,…
- CVE-2013-1132Multiple cross-site scripting (XSS) vulnerabilities in Cisco…
- CVE-2013-1133Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2…
Are you affected by CVE-2013-1125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
