CVE-2013-3473
Published Sep 20, 2013
Last updated 11 years ago
Overview
- Description
- The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C7857FD-FF8A-4222-89B2-8E36D81C16A6", "versionEndIncluding": "9.1" }, { "criteria": "cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51C22E91-188C-4927-8CBB-E242040F6AEC" }, { "criteria": "cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A393353-5FD1-4760-9A06-B7F8A2121B6C" }, { "criteria": "cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BEC9F2A8-B9ED-4FBC-A678-E1017E67B096" }, { "criteria": "cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D59739B-0E2E-475A-971B-EE0687667A65" } ], "operator": "OR" } ] } ]