Vulnerability Name: | CVE-2013-1205 (CCN-84766) | ||||||||
Assigned: | 2013-06-04 | ||||||||
Published: | 2013-06-04 | ||||||||
Updated: | 2013-06-06 | ||||||||
Summary: | The Event Center module in Cisco WebEx Meetings Server does not perform request authentication in all intended circumstances, which allows remote attackers to discover host keys and event passwords via crafted URLs, aka Bug ID CSCue62485. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-1205 Source: CCN Type: SA53731 Cisco WebEx Meetings Server Information Disclosure Vulnerability Source: CCN Type: Cisco Security Notice Cisco WebEx Meetings Server Information Disclosure Vulnerability Source: CISCO Type: Vendor Advisory 20130604 Cisco WebEx Meetings Server Information Disclosure Vulnerability Source: CCN Type: BID-60373 Cisco WebEx Meetings Server CVE-2013-1205 Information Disclosure Vulnerability Source: XF Type: UNKNOWN cisco-webex-cve20131205-info-disc(84766) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |