CVE-2013-3473

high
Published 2013-09-20 · Modified 2026-04-29
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-pc

Application impact

VendorProductVersionsFixed
ciscoprime_central_for_hosted_collaboration_solution_assurance{"endIncluding":"9.1"}
ciscoprime_central_for_hosted_collaboration_solution_assurance1.0
ciscoprime_central_for_hosted_collaboration_solution_assurance1.0.1
ciscoprime_central_for_hosted_collaboration_solution_assurance8.6
ciscoprime_central_for_hosted_collaboration_solution_assurance9.0

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.