CVE-2013-3429
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 10.19% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cisco/video surveillance manager
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsmVendor Advisory
- http://www.securityfocus.com/bid/61430
- http://www.securitytracker.com/id/1028827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85947
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130724-vsmVendor Advisory
- http://www.securityfocus.com/bid/61430
- http://www.securitytracker.com/id/1028827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85947
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.