5
CVSSv2

CVE-2013-3407

Published: 18/11/2013 Updated: 19/11/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and previous versions does not require authentication for unspecified pages, which allows remote malicious users to obtain sensitive information via a direct request, aka Bug ID CSCug65664.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco server provisioner

cisco server provisioner 6.4.0

cisco server provisioner 6.3.0

Vendor Advisories

A vulnerability in the web interface of Cisco Server Provisioner could allow an unauthenticated, remote attacker to access some pages directly that should require authentication The vulnerability is due to a failure to enforce access controls for the vulnerable pages An attacker could exploit this vulnerability by directly browsing to the vulner ...