CVE Vulnerabilities

CVE-2013-3473

Improper Authentication

Published: Sep 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Prime_central_for_hosted_collaboration_solution_assuranceCisco*9.1 (including)
Prime_central_for_hosted_collaboration_solution_assuranceCisco1.0 (including)1.0 (including)
Prime_central_for_hosted_collaboration_solution_assuranceCisco1.0.1 (including)1.0.1 (including)
Prime_central_for_hosted_collaboration_solution_assuranceCisco8.6 (including)8.6 (including)
Prime_central_for_hosted_collaboration_solution_assuranceCisco9.0 (including)9.0 (including)

Potential Mitigations

References