CVE Vulnerabilities

CVE-2013-3473

Improper Authentication

Published: Sep 20, 2013 | Modified: Sep 23, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Prime_central_for_hosted_collaboration_solution_assurance Cisco * 9.1 (including)
Prime_central_for_hosted_collaboration_solution_assurance Cisco 1.0 (including) 1.0 (including)
Prime_central_for_hosted_collaboration_solution_assurance Cisco 1.0.1 (including) 1.0.1 (including)
Prime_central_for_hosted_collaboration_solution_assurance Cisco 8.6 (including) 8.6 (including)
Prime_central_for_hosted_collaboration_solution_assurance Cisco 9.0 (including) 9.0 (including)

Potential Mitigations

References