PT-2013-4364 · Cisco · Cisco Server Provisioner
Published
2013-11-16
·
Updated
2013-11-19
·
CVE-2013-3407
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Server Provisioner versions 6.4.0 Patch 5-1301292331 and earlier
Description
The web interface does not require authentication for certain pages, allowing remote attackers to obtain sensitive information via a direct request.
Recommendations
For Cisco Server Provisioner versions 6.4.0 Patch 5-1301292331 and earlier, consider restricting access to the web interface until a patch is available. As a temporary workaround, limit access to sensitive information by implementing additional authentication mechanisms for the unspecified pages.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Server Provisioner