| Vulnerability Name: | CVE-2013-1128 (CCN-82042) | ||||||||
| Assigned: | 2013-02-11 | ||||||||
| Published: | 2013-02-11 | ||||||||
| Updated: | 2013-02-18 | ||||||||
| Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in the server in Cisco Unified MeetingPlace before 7.1(2.2000) allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuc64903. Note: some of these details are obtained from third party information. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-352 | ||||||||
| Vulnerability Consequences: | Cross-Site Scripting | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-1128 Source: CCN Type: SA52194 Cisco Unified MeetingPlace Cross-Site Request Forgery Vulnerability Source: SECUNIA Type: Vendor Advisory 52194 Source: CCN Type: Cisco Security Notice Cisco Unified MeetingPlace Server Cross-Site Request Forgery Vulnerability Source: CISCO Type: Vendor Advisory 20130211 Cisco Unified MeetingPlace Server Cross-Site Request Forgery Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=28217 Source: CCN Type: BID-57937 Cisco Unified MeetingPlace CVE-2013-1128 Cross Site Request Forgery Vulnerability Source: XF Type: UNKNOWN cisco-unifiedmeetingplace-webinterface-csrf(82042) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||