{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:38Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20130422-CVE-2013-1195","slug":"cisco-sa-20130422-cve-2013-1195","vendor":"Cisco","title":"Cisco Adaptive Security Appliance Software and Firewall Services Module Software Time-Range Object Access List Bypass Vulnerability","summary":"A vulnerability in the implementation of the time-range object could allow an unauthenticated, remote attacker to bypass access lists that are using the time-range option. The vulnerability is due to improper implementation of the code for the time-range object, when the periodic command is used. Due to this issue, the time-range object may have no effect. Therefore, depending on the access-list statement (permit or deny), an attacker could bypass the access list. An attacker could exploit this vulnerability by sending traffic through the affected system. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. Customers are advised to review the bug reports in the vendor announcements section for a current list of affected versions. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.","severity":"Medium","published_at":"2013-04-22T19:37:07Z","updated_at":"2013-04-22T19:37:07Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20130422-CVE-2013-1195","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20130422-CVE-2013-1195/csaf/Cisco-SA-20130422-CVE-2013-1195.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":2,"public_evidence_count":2,"kev_count":0,"highest_epss":0.01247},"cves":[{"id":"CVE-2013-1195","kev":false,"epss":{"score":0.01247,"percentile":0.65987,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"}}],"public_evidence":[{"product":{"name":"Cisco Adaptive Security Appliance (ASA) Software","slug":"cisco-adaptive-security-appliance-asa-software","vendor":"Cisco"},"cve":{"id":"CVE-2013-1195"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T00:29:51Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"8.4.1; 8.4.1.11; 8.4.1.3; 8.4.2; 8.4.2.8; 8.4.3; 8.4.3.8; 8.4.3.9; 8.4.4; 8.4.4.1; 8.4.4.3; 8.4.4.5; 8.4.4.9; 8.4.5; 8.4.5.6; 8.4.6","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01247,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"},"published_at":"2013-04-22T19:37:07Z","updated_at":"2013-04-22T19:37:07Z","advisory_updated_at":"2013-04-22T19:37:07Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20130422-CVE-2013-1195","row_display_order":1},{"product":{"name":"Cisco Firewall Services Module (FWSM)","slug":"cisco-firewall-services-module-fwsm","vendor":"Cisco"},"cve":{"id":"CVE-2013-1195"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T00:29:51Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Firewall Services Module (FWSM)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01247,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"},"published_at":"2013-04-22T19:37:07Z","updated_at":"2013-04-22T19:37:07Z","advisory_updated_at":"2013-04-22T19:37:07Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20130422-CVE-2013-1195","row_display_order":2}]}