Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-3473

Опубликовано: 20 сент. 2013
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:*:*:*:*:*:*:*:*
Версия до 9.1 (включая)
cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:8.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution_assurance:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00272
Низкий

7.8 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

EPSS

Процентиль: 50%
0.00272
Низкий

7.8 High

CVSS2

Дефекты

CWE-287