CVE-2003-0732

CRITICAL

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the ...

Affects 4 products across 1 vendor.

BCS7.19
CVSS 2.010.0
EPSS2.1%
Percentile80th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2003. A critical vulnerability affects Cisco systems (CVE-2003-0732). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2003-GLOBAL-000405-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2003-0732?
This vulnerability was disclosed in 2003. A critical vulnerability affects Cisco systems (CVE-2003-0732). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2003-0732?
CVE-2003-0732 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.1%.
Is CVE-2003-0732 actively exploited?
No confirmed active exploitation of CVE-2003-0732 as of 2026-05-30.
How do I remediate CVE-2003-0732?
Priority: MEDIUM. Advisory: http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml PSIRT: [email protected]
What systems are affected by CVE-2003-0732?
CVE-2003-0732 affects: Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2003-0732
BSIDBS-2003-GLOBAL-000405-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2003-10-20
Last Modified2026-04-16
ICS Relevance55%
Domains
NETWORK-INFRA
SourceNVD
Official Description

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Resource Manager
Cisco Resource Manager Essentials
Cisco Ciscoworks Common Management Foundation
Cisco Ciscoworks Cd1
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 8314 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash330e91b9771404d3c6cd7cdfbcd98eac312f6adfc227ad5db0c8287b51e9263f7df681cfe503dac10ce9db5e3e252685bbb0dc389c2172216cfc6a53ac94a8e2
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →