VulnerabilityModified
CVE-2013-3438
The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and read unspecified web pages via crafted parameters, aka Bug ID CSCuh86385.
MEDIUM 5.0EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and read unspecified web pages via crafted parameters, aka Bug ID CSCuh86385.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/unified meetingplace web conferencing
- Source
- psirt@cisco.com
References
- http://osvdb.org/95583
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3438Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30186Vendor Advisory
- http://osvdb.org/95583
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3438Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30186Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.