← Vulnerability feed

Vulnerability record · CVE-2011-2738 · published 19 September 2011

CVE-2011-2738: Cisco unified service monitor vulnerability

Cisco · Unified Service Monitor

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

10.0 CVSS 2.0 High EPSS 11% · top 4.3%
10.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/45979 Vendor Advisory
http://secunia.com/advisories/46016 Vendor Advisory
http://secunia.com/advisories/46052 Vendor Advisory
http://secunia.com/advisories/46053 Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml Vendor Advisory
http://www.osvdb.org/75442
http://www.securityfocus.com/archive/1/519646/100/0/threaded
http://www.securityfocus.com/bid/49627
http://www.securityfocus.com/bid/49644
http://www.securitytracker.com/id?1026046
http://www.securitytracker.com/id?1026047
http://www.securitytracker.com/id?1026048
http://www.securitytracker.com/id?1026059
https://exchange.xforce.ibmcloud.com/vulnerabilities/69828
http://secunia.com/advisories/45979 Vendor Advisory
http://secunia.com/advisories/46016 Vendor Advisory
http://secunia.com/advisories/46052 Vendor Advisory
http://secunia.com/advisories/46053 Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml Vendor Advisory
http://www.osvdb.org/75442
http://www.securityfocus.com/archive/1/519646/100/0/threaded
http://www.securityfocus.com/bid/49627
http://www.securityfocus.com/bid/49644
http://www.securitytracker.com/id?1026046
http://www.securitytracker.com/id?1026047
http://www.securitytracker.com/id?1026048
http://www.securitytracker.com/id?1026059
https://exchange.xforce.ibmcloud.com/vulnerabilities/69828

Track CVE-2011-2738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-3036Ciscoworks common services memory buffer overflow vulnerabilityMultiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote at…EPSS 6.0%10.0CVE-2009-1161Ciscoworks common services path traversal vulnerabilityDirectory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Uni…EPSS 13%7.5CVE-2011-0960Cisco unified operations manager sql injection vulnerabilityMultiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands…EPSS 3.8%6.5CVE-2013-3437Cisco unified operations manager sql injection vulnerabilitySQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary …EPSS 1.0%5.0CVE-2013-5488Cisco prime lan management solution improper input validation vulnerabilityCisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified…EPSS 1.6%4.3CVE-2013-3439Cisco unified operations manager cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a cra…EPSS 1.8%4.3CVE-2013-3440Cisco unified operations manager cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cisco Unified Operations Manager allow remote attackers to…EPSS 1.2%4.3CVE-2013-3416Cisco unified operations manager cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the web framework in the unified-communications management implementation in Cisco Unified Operations Man…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2011-2738), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.