4.3
CVSSv2

CVE-2013-3409

Published: 10/10/2013 Updated: 10/10/2013
CVSS v2 Base Score: 4.3 | Impact Score: 6.4 | Exploitability Score: 3.1
VMScore: 383
Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in Cisco Prime Central for HCS portal could allow an authenticated, local malicious user to retrieve the credentials for accounts. The vulnerability is due to plaintext logging of credentials to temporary files with inadequate permissions. An attacker could exploit this vulnerability by accessing the files to acquire credentials and using them to access internal application components, such as the database. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. An attacker would need to authenticate and have local access to the targeted device. This access requirement decreases the likelihood of a successful attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime central for hosted collaboration solution -

Vendor Advisories

A vulnerability in Cisco Prime Central for HCS portal could allow an authenticated, local attacker to retrieve the credentials for accounts The vulnerability is due to plaintext logging of credentials to temporary files with inadequate permissions An attacker could exploit this vulnerability by accessing the files to acquire credentials and usi ...