Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsm - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/61431 - | |
References | () http://www.securitytracker.com/id/1028827 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/85945 - |
Information
Published : 2013-07-25 15:53
Updated : 2024-11-21 01:53
NVD link : CVE-2013-3431
Mitre link : CVE-2013-3431
CVE.ORG link : CVE-2013-3431
JSON object : View
Products Affected
cisco
- video_surveillance_manager
CWE
CWE-287
Improper Authentication