The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allows remote attackers to obtain sensitive information via a direct request, aka Bug ID CSCug65664.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Server_provisioner | Cisco | * | 6.4.0 (including) |
Server_provisioner | Cisco | 6.3.0 (including) | 6.3.0 (including) |
Server_provisioner | Cisco | 6.4.0 (including) | 6.4.0 (including) |
Server_provisioner | Cisco | 6.4.0-patch_1204040128 (including) | 6.4.0-patch_1204040128 (including) |
Server_provisioner | Cisco | 6.4.0-patch_2-1112122225 (including) | 6.4.0-patch_2-1112122225 (including) |
Server_provisioner | Cisco | 6.4.0-patch_3-1208021049 (including) | 6.4.0-patch_3-1208021049 (including) |