A Cisco bug report warns of a critical vulnerability in the LAN Management Product CiscoWorks. According to the report, a buffer overflow in the web server module of the Common Services component allows for the injection and remote execution of arbitrary code. No prior authentication is required.