CVE-2013-3431
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsm
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | video_surveillance_manager | {"endIncluding":"6.3.3"} | |
| cisco | video_surveillance_manager | 1.1.0 | |
| cisco | video_surveillance_manager | 1.2.1 | |
| cisco | video_surveillance_manager | 2.0.0 | |
| cisco | video_surveillance_manager | 2.1 | |
| cisco | video_surveillance_manager | 2.1.2 | |
| cisco | video_surveillance_manager | 2.1.3 | |
| cisco | video_surveillance_manager | 2.1.4 | |
| cisco | video_surveillance_manager | 2.1.6 | |
| cisco | video_surveillance_manager | 2.1.7 | |
| cisco | video_surveillance_manager | 2.3.0 | |
| cisco | video_surveillance_manager | 2.3.1 | |
| cisco | video_surveillance_manager | 4.0.1 | |
| cisco | video_surveillance_manager | 4.2.0 | |
| cisco | video_surveillance_manager | 4.2.1 | |
| cisco | video_surveillance_manager | 6.3 | |
| cisco | video_surveillance_manager | 6.3.1 | |
| cisco | video_surveillance_manager | 6.3.2 | |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsm
- http://www.securityfocus.com/bid/61431
- http://www.securitytracker.com/id/1028827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85945
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsm
- http://www.securityfocus.com/bid/61431
- http://www.securitytracker.com/id/1028827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85945
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.