CVE-2011-2738

CRITICAL

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and...

Affects 6 products across 2 vendors.

BCS7.89
CVSS 2.010.0
EPSS11.0%
Percentile96th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2011. A critical vulnerability affects Cisco systems (CVE-2011-2738). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2011-GLOBAL-088410-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2011-2738?
This vulnerability was disclosed in 2011. A critical vulnerability affects Cisco systems (CVE-2011-2738). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2011-2738?
CVE-2011-2738 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 11.0%.
Is CVE-2011-2738 actively exploited?
No confirmed active exploitation of CVE-2011-2738 as of 2026-09-25.
How do I remediate CVE-2011-2738?
Priority: MEDIUM.
What systems are affected by CVE-2011-2738?
CVE-2011-2738 affects: Cisco, Cisco, Cisco, Emc, Emc, Emc.
Vulnerability Details
CVE IDCVE-2011-2738
BSIDBS-2011-GLOBAL-088410-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2011-09-19
Last Modified2026-06-16
ICS Relevance55%
Domains
NETWORK-INFRA
SourceNVD
Official Description

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code v CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Ciscoworks Lan Management Solution —
Cisco Unified Operations Manager —
Cisco Unified Service Monitor —
Emc Ionix Acm —
Emc Ionix Asam —
Emc Ionix Ip —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 5488 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash540250cf79e929c030327457c8ca9eec8cde6fb7f5265fab193df60795b2176cc2d8398c3dc9050c0b9bc6f2775b75650791f0558b7950f8fe1babf3c21bb9c2
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2009-1167 10.0 Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2007-4241 10.0 Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →