PT-2013-4364 · Cisco · Cisco Server Provisioner

Published

2013-11-16

·

Updated

2013-11-19

·

CVE-2013-3407

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Server Provisioner versions 6.4.0 Patch 5-1301292331 and earlier
Description The web interface does not require authentication for certain pages, allowing remote attackers to obtain sensitive information via a direct request.
Recommendations For Cisco Server Provisioner versions 6.4.0 Patch 5-1301292331 and earlier, consider restricting access to the web interface until a patch is available. As a temporary workaround, limit access to sensitive information by implementing additional authentication mechanisms for the unspecified pages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3407

Affected Products

Cisco Server Provisioner