CVE-2013-3407

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allows remote attackers to obtain sensitive information via a direct request, aka Bug ID CSCug65664.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:server_provisioner:*:patch_5-1301292331:*:*:*:*:*:*
cpe:2.3:a:cisco:server_provisioner:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:server_provisioner:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:server_provisioner:6.4.0:patch_1204040128:*:*:*:*:*:*
cpe:2.3:a:cisco:server_provisioner:6.4.0:patch_2-1112122225:*:*:*:*:*:*
cpe:2.3:a:cisco:server_provisioner:6.4.0:patch_3-1208021049:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3407 - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3407 - Vendor Advisory
References () http://tools.cisco.com/security/center/viewAlert.x?alertId=31776 - Vendor Advisory () http://tools.cisco.com/security/center/viewAlert.x?alertId=31776 - Vendor Advisory

Information

Published : 2013-11-18 03:55

Updated : 2024-11-21 01:53


NVD link : CVE-2013-3407

Mitre link : CVE-2013-3407

CVE.ORG link : CVE-2013-3407


JSON object : View

Products Affected

cisco

  • server_provisioner
CWE
CWE-264

Permissions, Privileges, and Access Controls