CVE-2010-3036
CVE-2010-3036 is a critical-severity vulnerability in Cisco Ciscoworks Common Services with a CVSS 2.0 base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Critical (CVSS 2.0 base score 10.0)
- EPSS exploit prediction: 6% (93rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Cisco Ciscoworks Common Services
- Published:
- Last modified:
Description
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
Frequently asked questions
- What is CVE-2010-3036?
- Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
- How severe is CVE-2010-3036?
- CVE-2010-3036 has a CVSS 2.0 base score of 10.0, rated critical severity.
- Is CVE-2010-3036 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 6% (93rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2010-3036?
- CVE-2010-3036 primarily affects Cisco Ciscoworks Common Services. In total, 21 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2010-3036?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2010-3036 published?
- CVE-2010-3036 was published on 2010-10-29 and last updated on 2026-06-16.
References
- http://osvdb.org/68927
- http://secunia.com/advisories/42011
- http://securitytracker.com/id?1024646
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b51501.shtml
- http://www.securityfocus.com/bid/44468
- http://www.vupen.com/english/advisories/2010/2793
Affected products (21)
- cpe:2.3:a:cisco:ciscoworks_common_services:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_common_services:3.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_common_services:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_common_services:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_common_services:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_common_services:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_lan_management_solution:2.6:update:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.0:december_2007:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:qos_policy_manager:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:qos_policy_manager:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:qos_policy_manager:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:security_manager:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:security_manager:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:telepresence_readiness_assessment_manager:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_operations_manager:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_operations_manager:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_operations_manager:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_service_monitor:2.0.1:*:*:*:*:*:*:*
More vulnerabilities in Cisco Ciscoworks Common Services
- CVE-2009-1161 — Critical (CVSS 10.0): Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on…
- CVE-2008-2054 — Critical (CVSS 9.3): Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute…
- CVE-2011-3310 — Critical (CVSS 9.0): The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management…
- CVE-2004-0079 — High (CVSS 7.5): The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause…
- CVE-2011-0966 — Medium (CVSS 6.8): Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common…
- CVE-2011-2042 — Medium (CVSS 5.0): The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote…
All CVEs affecting Cisco Ciscoworks Common Services →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-105285 — Critical (CVSS 10.0): A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function…
- CVE-2026-104610 — Critical (CVSS 10.0): A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function…
- CVE-2026-101039 — Critical (CVSS 10.0): A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element…
- CVE-2026-96257 — Critical (CVSS 10.0): A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element…
- CVE-2026-94089 — Critical (CVSS 10.0): A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file…
- CVE-2026-94003 — Critical (CVSS 10.0): A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file…