6.8
CVSSv2

CVE-2013-3395

Published: 02/07/2013 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote malicious users to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263, CSCuh70323, and CSCuh26634.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance firmware -

cisco content security management appliance -

cisco web security appliance -

Exploits

Cisco IronPort Security Management Appliance M170 version 791-030 suffers from cross site scripting and cross site request forgery vulnerabilities ...