Vulnerability Name: | CVE-2013-3438 (CCN-85936) | ||||||||
Assigned: | 2013-07-23 | ||||||||
Published: | 2013-07-23 | ||||||||
Updated: | 2016-09-16 | ||||||||
Summary: | The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and read unspecified web pages via crafted parameters, aka Bug ID CSCuh86385. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-3438 Source: OSVDB Type: UNKNOWN 95583 Source: CCN Type: SA54281 Cisco Unified MeetingPlace Web Conferencing Security Bypass Security Issue Source: CCN Type: Cisco Security Notice Cisco Unified MeetingPlace Web Conferencing Authorization By-pass Vulnerability Source: CISCO Type: Vendor Advisory 20130723 Cisco Unified MeetingPlace Web Conferencing Authorization By-pass Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=30186 Source: CCN Type: BID-61417 Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability Source: XF Type: UNKNOWN cisco-meetingplace-cve20133438-sec-bypass(85936) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |