CVE-2013-3384
CVE-2013-3384 is a critical-severity vulnerability in Cisco Ironport Asyncos with a CVSS 2.0 base score of 9.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 2.0 base score 9.0)
- EPSS exploit prediction: 4% (88th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Cisco Ironport Asyncos
- Published:
- Last modified:
Description
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.2.2-110, 7.7 before 7.7.0-213, and 7.8 and 7.9 before 7.9.1-102 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL, aka Bug IDs CSCzv85726, CSCzv44633, and CSCzv24579.
Frequently asked questions
- What is CVE-2013-3384?
- The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.2.2-110, 7.7 before 7.7.0-213, and 7.8 and 7.9 before 7.9.1-102 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL, aka Bug IDs CSCzv85726, CSCzv44633, and CSCzv24579.
- How severe is CVE-2013-3384?
- CVE-2013-3384 has a CVSS 2.0 base score of 9.0, rated critical severity.
- Is CVE-2013-3384 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (88th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-3384?
- CVE-2013-3384 primarily affects Cisco Ironport Asyncos. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-3384?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2013-3384 published?
- CVE-2013-3384 was published on 2013-06-27 and last updated on 2026-06-16.
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130626-esa
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130626-sma
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130626-wsa
Affected products (8)
- cpe:2.3:o:cisco:ironport_asyncos:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.5:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.7:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ironport_asyncos:7.9:*:*:*:*:*:*:*
More vulnerabilities in Cisco Ironport Asyncos
- CVE-2013-3383 — Critical (CVSS 9.0): The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838,…
- CVE-2014-2119 — High (CVSS 8.5): The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before…
- CVE-2013-3386 — High (CVSS 7.8): The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance…
- CVE-2013-3385 — High (CVSS 7.8): The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013,…
- CVE-2014-3289 — Medium (CVSS 4.3): Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security…
- CVE-2009-1162 — Medium (CVSS 4.3): Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on…
All CVEs affecting Cisco Ironport Asyncos →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…