CVE-2013-5497
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted…
Does this matter?
Lower severity and a low EPSS score (1.91%). Track it; it rarely justifies an emergency change on its own.
Description
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cisco/intrusion prevention system
- Source
- psirt@cisco.com
References
- http://osvdb.org/97525
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5497Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30913Vendor Advisory
- http://www.securityfocus.com/bid/62517Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029057Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87280
- http://osvdb.org/97525
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5497Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30913Vendor Advisory
- http://www.securityfocus.com/bid/62517Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029057Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87280
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.