CVE-2013-3469
Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection,…
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug ID CSCue50794.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/mobility services engine
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3469Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30617Vendor Advisory
- http://www.securityfocus.com/bid/62091Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028972Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3469Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30617Vendor Advisory
- http://www.securityfocus.com/bid/62091Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028972Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.